Description
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Scope is changed.
Published: 2026-08-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Commerce is vulnerable to a stored XSS flaw that allows a low‑privileged attacker to inject malicious scripts into form fields. When a victim visits the page containing the compromised field, the script runs in their browser and may elevate the attacker’s access or take control of the victim’s account. The impact is chiefly confidentiality and integrity of the victim session, and it alters the scope of the affected system.

Affected Systems

Affected products include Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific version information was provided, so all current installations of these products require assessment.

Risk and Exploitability

The CVSS v3.1 score of 7.7 indicates a high severity, but the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV, and the exploit requires conditions beyond the attacker’s direct control. The likely attack vector is via a low‑privileged authenticated user submitting data to the vulnerable form, and this inference is noted where explicit information is absent.

Generated by OpenCVE AI on August 12, 2026 at 20:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch released in Adobe Security Bulletin APSB26‑92 to remediate the stored XSS failure.
  • Disable or restrict the vulnerable form fields until the patch is applied, ensuring that user input is properly escaped when rendered.
  • Implement a Content Security Policy that limits inline script execution and restricts allowlist sources to mitigate accidental script runs.
  • If a patch is not immediately available, sanitize all user‑supplied input on the server side to strip or encode script payloads.

Generated by OpenCVE AI on August 12, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe magento Open Source

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Scope is changed.
Title Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:14.921Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48414

cve-icon Vulnrichment

Updated: 2026-08-11T20:01:58.909Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-11T18:17:31.313

Modified: 2026-08-28T00:17:58.820

Link: CVE-2026-48414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')