CVE-2026-21291: Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21291?
CVE-2026-21291 is considered a critical severity vulnerability that could allow a high-privileged attacker to exploit stored XSS.
How do I fix CVE-2026-21291?
To fix CVE-2026-21291, upgrade to Adobe Commerce versions 2.4.4-p17 or later.
What types of attacks are possible with CVE-2026-21291?
CVE-2026-21291 allows attackers to perform stored cross-site scripting, potentially executing malicious scripts in users' browsers.
Which versions of Adobe Commerce are affected by CVE-2026-21291?
CVE-2026-21291 affects Adobe Commerce versions 2.4.4-p16 and earlier.
Who is at risk of CVE-2026-21291?
High-privileged users of Adobe Commerce are at risk of CVE-2026-21291 as they could be targeted for exploitation of the XSS vulnerability.