Junglewise Threat Intelligence

CVE-2026-27234: Adobe Experience Manager stored XSS in form fields

CVE-2026-27234 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager is a content management platform used by enterprises to create, manage, and publish digital experiences. A stored cross-site scripting (XSS) vulnerability in form handling allows attackers to inject malicious JavaScript that executes when administrators or users view affected pages, potentially compromising account credentials, session tokens, or triggering unwanted actions within the application.

Technical details

The vulnerability is a stored (persistent) cross-site scripting flaw in Adobe Experience Manager versions 6.5.23 and earlier. An attacker can inject malicious JavaScript into vulnerable form fields; the payload persists in the application's database and is executed in the browser of any user who views the affected page, without requiring authentication or user interaction beyond normal navigation. This enables session hijacking, credential theft, defacement, and lateral movement within the application. Adobe has released security updates to address this issue.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References