CVE-2026-34686: Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34686?
CVE-2026-34686 is classified as a critical severity vulnerability due to its potential for allowing arbitrary script execution.
How do I fix CVE-2026-34686?
To resolve CVE-2026-34686, upgrade Adobe Commerce to version 2.4.9-beta2 or later.
Who is affected by CVE-2026-34686?
CVE-2026-34686 affects Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, and earlier versions.
What is the nature of the vulnerability described in CVE-2026-34686?
CVE-2026-34686 is a stored Cross-Site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts.
What are the potential consequences of CVE-2026-34686?
If exploited, CVE-2026-34686 could allow low-privileged attackers to execute malicious scripts within the context of the application.