Executive brief
Adobe Experience Manager, a widely-used content management platform, contains a stored cross-site scripting vulnerability in form fields. A low-privileged user could inject malicious JavaScript code into these fields, which would then execute in the browsers of other users viewing the affected page—potentially compromising session data, stealing credentials, or performing unauthorized actions on their behalf.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Adobe Experience Manager's form field handling, where user-supplied input is not properly sanitized before being persisted and rendered in the browser. An attacker with low-level privileges can inject arbitrary JavaScript into vulnerable form fields; the malicious script is stored and executed whenever any user views the page containing the infected field. The scope has been changed (likely indicating broader impact than initially assessed). No patch release date is specified in the advisory.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed