Junglewise Threat Intelligence

CVE-2026-27240: Adobe Experience Manager stored XSS in form fields

CVE-2026-27240 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager (a content management and authoring platform used by many large enterprises) contains a stored cross-site scripting vulnerability in form field handling. A low-privileged attacker can inject malicious scripts that execute in the browsers of any user viewing the affected content, potentially enabling account takeover, data theft, or malware distribution.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier, where user input in form fields is not properly sanitized before storage and display. An attacker with low-level privileges can inject malicious JavaScript into vulnerable form fields; when any user subsequently views the page containing the field, the script executes in their browser with their privileges. The vulnerability requires attacker authentication to inject the payload but does not require user interaction beyond normal browsing. Patches are available through Adobe's security bulletins.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References