ZeroHour

CVE-2026-76200

large

Stored XSS in Adobe Commerce (Magento) Can Hijack Admin and Customer Sessions

CVSS 3.1
9.3 critical
EPSS
<1%p38
Published
()
Modified
AI analysis

CVE-2026-76200 is a stored Cross-Site Scripting (CWE-79) flaw in Adobe Commerce that lets an attacker persist malicious JavaScript in vulnerable form fields. When a victim later browses to a page containing the injected field, the script executes in their browser with the CVSS scope-change (S:C) indicating the impact crosses component boundaries, such as reaching an admin or another user's session. An attacker who succeeds can gain elevated access or control over the victim's account or session, which on an e-commerce platform could mean admin panel access or compromise of customer accounts. Affected products are Adobe Commerce, Magento, and the Commerce B2B offering, with specific affected and fixed version ranges not stated in the available data. Exploitation has not been confirmed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.8% chance of exploitation within 30 days.

What to do: Patch by upgrading to the release specified in Adobe's security bulletin for this CVE, prioritizing stores with internet-exposed account or checkout forms where the vulnerable fields can be populated. Until patched, restrict and sanitize input to the affected form fields and review recent admin/customer session activity for signs of hijacking. Because scope is 'changed', assume a successful injection could compromise higher-privileged sessions than the field's own context, so validate any admin accounts that interacted with attacker-modified content.

Affected
Adobe Commerce
Adobe Magento
Adobe Commerce B2B
Estimated exposure
largeorder of tens of thousands of live stores (≈50,000–150,000 Magento/Adobe Commerce deployments) — Public web-technology surveys such as BuiltWith and W3Techs place the Magento/Adobe Commerce platform family in the tens of thousands of live e-commerce sites, with the paid Adobe Commerce and B2B editions forming a substantial but smaller…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

Vendors
adobe
Products
magento, commerce, commerce b2b
Ecosystems
E-commerce
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.