Executive brief
Adobe Experience Manager, a popular enterprise content management and digital experience platform, contains a stored cross-site scripting vulnerability in form field handling. An attacker can inject malicious JavaScript code that persists in the system and executes in the browsers of users who view the affected page, potentially compromising user sessions, stealing credentials, or redirecting users to malicious sites.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier affecting form field processing. The vulnerability stems from insufficient input sanitization or output encoding in form handling components, allowing attackers to inject and persist malicious JavaScript payloads. An authenticated or unauthenticated attacker (depending on form accessibility) can inject scripts that execute in the context of any user's browser when the affected form page is viewed. The injected payload remains stored in the application, enabling repeated exploitation without requiring the attacker to be present. Patches or updates are expected from Adobe's security advisory APSB26-24.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed
- advisory: APSB26-24