Junglewise Threat Intelligence

CVE-2026-27229: Adobe Experience Manager stored XSS in form fields

CVE-2026-27229 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management and digital experience platform used by enterprises to build websites and applications, contains a stored cross-site scripting vulnerability in form fields. An attacker can inject malicious scripts that execute in the browsers of users who view the affected pages, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of victims.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Experience Manager's form field handling that fails to properly sanitize user input. An attacker with the ability to inject content into vulnerable form fields can persist malicious JavaScript in the application's database. When other users (including administrators) browse to pages containing the affected fields, the stored script executes in their browser context with their privileges. This requires the attacker to have sufficient access to modify form content, and the impact depends on the victim's role and permissions within AEM.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References