Junglewise Threat Intelligence

CVE-2026-27235: Adobe Experience Manager stored XSS in form fields

CVE-2026-27235 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager is a web content management platform used by enterprises to create and manage digital experiences. A low-privileged attacker can inject malicious scripts into form fields that are stored in the system; when other users view these pages, the scripts execute in their browsers, potentially compromising user sessions, stealing credentials, or performing unauthorized actions on their behalf.

Technical details

This is a stored (persistent) Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier, affecting form field handling. The vulnerability allows a low-privileged attacker to inject malicious JavaScript into vulnerable form fields without proper input sanitization or output encoding. When authenticated or unauthenticated users browse to pages containing the injected payload, the malicious script executes in their browser context. An attacker with low privileges can achieve account compromise, session hijacking, or lateral movement. Patches are expected from Adobe's security advisory APSB26-24.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References