Stored XSS Vulnerability in Adobe Commerce Affects User Data Security
CVE-2026-76201

9.3CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 September 2026

What is CVE-2026-76201?

Adobe Commerce has a vulnerability that may allow attackers to conduct stored Cross-Site Scripting (XSS) attacks. By exploiting this flaw, an attacker can inject harmful scripts into vulnerable form fields. When a user subsequently accesses the affected page, the malicious JavaScript executes in the victim's browser. This can lead to unauthorized access and control over the victim's session or account, resulting in potential data theft or manipulation. Ensuring that affected products are updated and secure is critical to preventing such security breaches.

Affected Version(s)

Adobe Commerce 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug

Adobe Commerce B2B 0 <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug

Magento Open Source 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.