Junglewise Threat Intelligence

CVE-2026-27224: Adobe Experience Manager stored XSS in form fields

CVE-2026-27224 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used enterprise content management and digital experience platform, contains a stored cross-site scripting vulnerability in form field handling. An attacker can inject malicious JavaScript code into vulnerable form fields, and when legitimate users visit pages containing these fields, the malicious code executes in their browsers, potentially stealing credentials, session tokens, or redirecting users to phishing sites.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier, affecting form field input validation or output encoding. The vulnerability exists in the form field component, where user-supplied input is not properly sanitized or encoded before being persisted in the content repository and subsequently rendered in victims' browsers. An unauthenticated attacker can inject malicious JavaScript into vulnerable form fields; when an authenticated user or administrator browses to the page containing the injected payload, the script executes in their security context. The attack requires the form to be accessible and for a user to view the compromised page, but no special privileges are needed to inject the payload. Adobe has released patches to address this issue in later versions.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References