Stored Cross-Site Scripting Vulnerability in Adobe Commerce
CVE-2026-48414
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-48414?
Adobe Commerce has a vulnerability that allows low-privileged attackers to inject harmful scripts into form fields. Users browsing affected pages may unknowingly execute malicious JavaScript in their browsers. This can lead to unauthorized access and control over user sessions, depending on various conditions that the attacker cannot manipulate. Protecting against this vulnerability is crucial to ensure user session integrity and data security.
Affected Version(s)
Adobe Commerce 0 <= 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
Adobe Commerce 0 <= 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
Adobe Commerce B2B 0 <= 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul