Junglewise Threat Intelligence

CVE-2026-27228: Adobe Experience Manager stored cross-site scripting in form fields

CVE-2026-27228 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager is a content management and digital asset management platform used by enterprises to create and manage web content and marketing materials. A stored cross-site scripting vulnerability in form fields allows attackers with low privileges to inject malicious scripts that execute in other users' browsers, potentially leading to account compromise, session hijacking, or data theft when victims interact with affected content.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier, located in vulnerable form field handling. The vulnerability allows low-privileged attackers to inject malicious JavaScript into form fields, which is then persistently stored and executed when other users browse pages containing the affected fields. The attack requires the attacker to have some level of access to submit or modify form data. No patch information is currently available in the advisory; vendors and users should monitor Adobe's security bulletins for updates.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References