Junglewise Threat Intelligence

CVE-2026-27241: Adobe Experience Manager stored XSS in form fields

CVE-2026-27241 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform, contains a stored cross-site scripting vulnerability in form field handling. An attacker with low-level system access can inject malicious JavaScript code into form fields, which then executes in the browsers of any user viewing that content. This could allow attackers to steal user sessions, credentials, or perform actions on behalf of legitimate users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Adobe Experience Manager 6.5.23 and earlier in the form field processing component. The vulnerability arises from insufficient input validation or output encoding of user-supplied data in form fields. A low-privileged attacker can inject malicious JavaScript payloads that are stored in the application database and subsequently executed in the context of other users' browsers when they interact with the affected form. No special preconditions or authentication bypass are required—the attacker must only have form submission capabilities. Patches are available through Adobe's security advisory APSB26-24.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References