Executive brief
Adobe Experience Manager, a widely-used content management platform, contains a stored cross-site scripting (XSS) vulnerability in form field handling that allows a low-privileged user to inject malicious scripts. When other users (including administrators) view pages containing the compromised form fields, the injected JavaScript executes in their browsers, potentially compromising their sessions, stealing credentials, or triggering unwanted actions on their behalf.
Technical details
This is a stored cross-site scripting (XSS) vulnerability affecting Adobe Experience Manager's form field validation and output encoding. A low-privileged authenticated attacker can inject malicious JavaScript payloads into vulnerable form fields; the injected content is persisted in the application's data store and executed in the context of any user's browser when they access the affected page. The vulnerability requires the attacker to have initial access to the application (low-privilege user account), but no special user interaction is required from the victim beyond normal page browsing. The scope is changed, indicating the vulnerability can impact resources beyond the vulnerable component itself. Patches are expected to be available through Adobe's regular security update channels.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed