Executive brief
Adobe Experience Manager, a widely used enterprise content management and digital experience platform, contains a stored cross-site scripting vulnerability in form field handling. A low-privileged attacker can inject malicious JavaScript code into vulnerable form fields, which is then executed in the browsers of other users who view the affected page, potentially allowing credential theft, session hijacking, or unauthorized actions on behalf of the victim.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier, where user-supplied input in form fields is not properly sanitized or encoded before being rendered in victims' browsers. The vulnerability requires a low-privileged authenticated user or one with form modification capabilities to inject the malicious payload into the vulnerable form field. The injected script persists in the application's backend and executes whenever another user accesses the page containing the compromised form field. An attacker can steal session tokens, perform actions as the victim, or redirect users to malicious sites. Patched versions should be available from Adobe's security advisory APSB26-24.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed
- 2026-03-11: advisory: Adobe security advisory APSB26-24