Executive brief
Adobe Experience Manager, a widely-used content management and digital experience platform, contains a stored cross-site scripting vulnerability in form field handling. An attacker with low-level access could inject malicious scripts that persist in the application and execute in the browsers of other users viewing the affected page, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of compromised users.
Technical details
This stored (persistent) cross-site scripting vulnerability exists in Adobe Experience Manager versions 6.5.23 and earlier due to insufficient input sanitization or output encoding in form field components. A low-privileged attacker can inject arbitrary JavaScript code into vulnerable form fields; the malicious payload is stored in the application and executed when any user views the affected page in their browser. No special authentication or network positioning is required beyond basic application access. An attacker can achieve account takeover, session hijacking, or perform actions in the context of the victim's authenticated session. Users should upgrade to patched versions when available.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed: CVE-2026-27244 published