Junglewise Threat Intelligence

CVE-2026-27225: Adobe Experience Manager stored XSS in form fields

CVE-2026-27225 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management platform used by enterprises to author and publish digital content, contains a stored cross-site scripting vulnerability in form field handling. A low-privileged user can inject malicious JavaScript that executes in the browsers of other users viewing the affected pages, potentially leading to session hijacking, credential theft, or unauthorized actions performed on their behalf.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Experience Manager versions 6.5.23 and earlier, where malicious scripts can be injected into vulnerable form fields. An attacker with low-privileged access can inject JavaScript that persists in the application's database. When a victim accesses pages containing the compromised field, the malicious script executes in their browser context. No special preconditions beyond low-privilege access are required to inject the payload. Adobe has released security advisories regarding this issue (APSB26-24).

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References