Executive brief
Adobe Experience Manager, a widely-used content management platform for building digital experiences, is vulnerable to stored cross-site scripting (XSS) attacks in form fields. A low-privileged attacker can inject malicious scripts that execute in other users' browsers when they access the affected form, potentially enabling account compromise, session hijacking, or data theft without requiring the attacker to be an administrator.
Technical details
The vulnerability is a stored (persistent) cross-site scripting flaw in Adobe Experience Manager's form field handling, where user-supplied input is not properly sanitized or encoded before being displayed to other users. An attacker with low-level access can inject arbitrary JavaScript into vulnerable form fields; the malicious script is stored and executed in the browser of any victim who views the affected page. The scope is changed, indicating the attack impacts more than just the attacker's own session. No patch availability information is provided in the advisory.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed