Executive brief
Adobe Experience Manager is a content management system used by enterprises to create and manage digital experiences. A stored cross-site scripting vulnerability allows attackers to inject malicious scripts into form fields that are executed when other users view the affected page, potentially enabling credential theft, session hijacking, or data exfiltration without requiring the victim to click a suspicious link.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier. The vulnerability exists in form field handling, where user-supplied input is not properly sanitized before being stored and reflected in victims' browsers. An attacker with the ability to interact with vulnerable form fields can inject malicious JavaScript that persists in the application and executes in the context of any user who views the affected page. No patch information is currently available in the advisory, though users should watch for updates from Adobe (APSB26-24).
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed