Executive brief
Adobe Experience Manager contains a stored cross-site scripting vulnerability in form fields that allows low-privileged users to inject malicious scripts. When administrators or other users view pages containing the affected fields, their browsers execute the injected scripts, potentially leading to unauthorized actions, data theft, or account compromise.
Technical details
The vulnerability is a stored XSS issue affecting Adobe Experience Manager's form field handling, allowing low-privileged attackers to inject malicious JavaScript that persists in the application database. The vulnerability has a changed scope, indicating an expanded attack surface beyond the original component. An authenticated attacker with low privileges can inject scripts into vulnerable form fields; when other users (including administrators) access the affected content, the malicious JavaScript executes in their browser context. This could enable session hijacking, credential theft, or privilege escalation. Patches are expected to be available through Adobe's security advisory APSB26-98.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed