CVE-2026-21292: Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21292?
The CVE-2026-21292 is considered a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-21292?
To fix CVE-2026-21292, update Adobe Commerce to version 2.4.9-alpha4 or later, or apply available patches from Adobe.
Who is affected by CVE-2026-21292?
CVE-2026-21292 affects Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, and several earlier versions of Adobe Commerce.
What types of attacks can exploit CVE-2026-21292?
CVE-2026-21292 can be exploited by attackers to perform stored cross-site scripting (XSS) attacks for data manipulation or unauthorized access.
What should I do if I can't immediately update for CVE-2026-21292?
If you cannot immediately update for CVE-2026-21292, consider implementing web application firewalls and limiting user permissions as a temporary mitigation.