Executive brief
Adobe Experience Manager, a widely-used content management and digital asset platform, contains a stored cross-site scripting (XSS) vulnerability in form field handling. An attacker could inject malicious JavaScript code into form fields that persists in the system, causing the script to execute in the browsers of users who view the affected pages. This could lead to account compromise, session hijacking, or credential theft from administrators and content editors.
Technical details
The vulnerability is a stored XSS flaw in Adobe Experience Manager versions 6.5.23 and earlier, stemming from insufficient input sanitization in form field processing. An attacker with access to create or modify form content can inject arbitrary JavaScript that is stored in the database and executed in victims' browsers when the form is viewed. The attack requires authenticated access to the authoring environment but poses a risk to all users who subsequently access the contaminated content. No initial patch availability is confirmed in the advisory, though Adobe has released security bulletin APSB26-24 addressing this issue.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed