Stored Cross-Site Scripting Vulnerability in Adobe Commerce
CVE-2026-76200

9.3CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 September 2026

What is CVE-2026-76200?

Adobe Commerce contains a vulnerability that allows attackers to exploit stored Cross-Site Scripting (XSS). This security flaw enables malicious actors to inject harmful JavaScript code into vulnerable form fields. When users interact with the affected page, the injected scripts can be executed in their browsers. This exploit could potentially grant the attacker escalated privileges, thereby compromising user sessions or accounts and posing a significant risk to data integrity and security.

Affected Version(s)

Adobe Commerce 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug

Adobe Commerce B2B 0 <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug

Magento Open Source 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.