CVE-2026-76201
largeStored XSS in Adobe Commerce and Magento Open Source lets attackers hijack sessions
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected by a stored cross-site scripting flaw (CWE-79) in which an attacker submits crafted content into a vulnerable form field and the malicious JavaScript later executes in any user's browser when they view the page containing that field. The attack vector requires no authentication (network vector, low complexity), but does require user interaction, and the changed scope means injected script can act beyond the vulnerable page, potentially giving the attacker elevated access or control over the victim's account or session. Any organization running an affected version of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source is exposed, especially storefronts that allow unauthenticated form submissions and admin panels reached by privileged users. Exploitation status: no public proof-of-concept is known, the flaw is not listed in CISA KEV, and EPSS estimates only a 0.8% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is documented yet.
What to do: Apply the patched release referenced in Adobe's security bulletin for CVE-2026-76201 across all Adobe Commerce, Adobe Commerce B2B, and Magento Open Source deployments (exact patched versions are listed in the bulletin). Until patching, review content stored in storefront and admin form fields for unexpected scripts, and restrict/review admin access since stored XSS payloads may already be persisted. If compromise is suspected, rotate credentials for privileged accounts, as changed scope means admin sessions can be hijacked.
| Adobe Commerce | — |
| Adobe Commerce B2B | — |
| adobe Magento (Magento Open Source) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
- Vendors
- adobe
- Products
- commerce, commerce b2b, magento
- Ecosystems
- E-commerce
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.