CVE-2026-48414 – Adobe Commerce
“A critical authorization flaw can elevate attacker access, while stored scripts put customer and administrator sessions at risk.”
Adobe Commerce is affected by three vulnerabilities involving authorization and stored cross-site scripting. CVE-2026-71362 has a CVSS score of 9.1, Critical severity, and can allow privilege escalation to sensitive resources without user interaction. CVE-2026-48414 has a CVSS score of 7.7, High severity. CVE-2026-48413 has a CVSS score of 8.7, High severity. Both High-severity flaws allow malicious JavaScript to be stored in vulnerable fields and executed in a victim's browser.
The Adobe Commerce security update addresses these weaknesses, reducing the risk of unauthorized privilege gains and compromise of user accounts or sessions.
Key Details
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- Low
- User Interaction
- Required
- CWE Classification
- CWE-79