Junglewise Threat Intelligence

CVE-2026-27242: Adobe Experience Manager stored XSS in form fields

CVE-2026-27242 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used enterprise content management system, contains a stored cross-site scripting (XSS) vulnerability in form field handling. A low-privileged attacker can inject malicious scripts into form fields that persist in the system; when legitimate users view pages containing these fields, the injected scripts execute in their browsers, potentially enabling session hijacking, credential theft, or unauthorized administrative actions.

Technical details

This is a stored XSS vulnerability in Adobe Experience Manager versions 6.5.23 and earlier, where user-supplied input in form fields is not properly sanitized or encoded before storage and display. The vulnerability requires low-level privileges to inject the malicious payload (e.g., authenticated user or operator account), but the execution occurs in the context of any user viewing the affected page. An attacker can craft JavaScript that executes when administrators or other users browse to pages containing the compromised form fields, potentially allowing account takeover, data exfiltration, or privilege escalation. Patches are expected to be available through Adobe's security bulletins (APSB26-24), though the advisory reference is currently inaccessible.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed
  • 2026-03-11: advisory: Adobe security bulletin APSB26-24 published

References