Executive brief
Adobe Experience Manager, a widely-used content management and digital experience platform, contains a stored cross-site scripting vulnerability in form field handling. A low-privileged user can inject malicious scripts that execute in the browsers of other users who view the affected form, potentially leading to account takeover, credential theft, or unauthorized actions performed on behalf of legitimate users.
Technical details
The vulnerability is a stored XSS (CWE-79) affecting form field input validation in Adobe Experience Manager. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; the script is stored server-side and executed in victims' browsers when they access pages containing the poisoned field. The scope is changed, indicating the attacker may impact other users or components. No special network access or user interaction beyond browsing is required on the victim side. Patches should be available from Adobe's security advisory APSB26-98.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: Adobe Security Bulletin APSB26-98