CVE-2026-48413

8.7

Adobe · Adobe Commerce

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields.

Executive summary

A stored Cross-Site Scripting vulnerability in Adobe Commerce allows authenticated low-privileged attackers to execute malicious scripts, posing a significant risk to administrative sessions and data integrity.

Vulnerability

This is a stored Cross-Site Scripting (XSS) vulnerability (CWE-79) residing in form fields. It requires an attacker to have low-level privileges to successfully inject and store the malicious payload.

Business impact

Successful exploitation allows an attacker to execute arbitrary JavaScript within the browser context of other users, including administrators. This can lead to unauthorized actions, session hijacking, and the potential theft of sensitive administrative data. Given the CVSS score of 8.7, this vulnerability represents a high risk to application integrity and user security.

Remediation

Immediate Action: Upgrade to the latest security release as specified in the Adobe security bulletin APSB26-92. Ensure the platform is updated to the corresponding August 2026 patch versions for your specific branch.

Proactive Monitoring: Monitor application access logs for unusual patterns in form submissions and review Content Security Policy (CSP) violation reports.

Compensating Controls: Implement a strict Content Security Policy (CSP) to restrict the execution of unauthorized scripts and utilize a Web Application Firewall (WAF) to filter malicious payloads from form inputs.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

The high severity of this vulnerability necessitates immediate attention. Organizations should prioritize updating their Adobe Commerce installations to the provided fixed versions to prevent potential session compromise and administrative account takeover.

More Adobe CVEs