Junglewise Threat Intelligence

CVE-2026-27237: Adobe Experience Manager stored XSS in form fields

CVE-2026-27237 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager is a content management system used by organizations to create and manage digital experiences. A low-privileged user can inject malicious scripts into form fields that execute when other users view the affected page, potentially enabling account takeover or data theft. The vulnerability affects versions 6.5.23 and earlier.

Technical details

This is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager's form handling functionality. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; the payload is persisted and executed in the browsers of victims who access the page containing the compromised field. The vulnerability requires attacker access to form submission but does not require victim interaction beyond viewing the affected page. No information on patch availability was accessible in the provided references.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References