Junglewise Threat Intelligence

CVE-2026-27244: Adobe Experience Manager stored XSS in form fields

CVE-2026-27244 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management and digital experience platform, contains a stored cross-site scripting vulnerability in form field handling. An attacker with low-level access could inject malicious scripts that persist in the application and execute in the browsers of other users viewing the affected page, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of compromised users.

Technical details

This stored (persistent) cross-site scripting vulnerability exists in Adobe Experience Manager versions 6.5.23 and earlier due to insufficient input sanitization or output encoding in form field components. A low-privileged attacker can inject arbitrary JavaScript code into vulnerable form fields; the malicious payload is stored in the application and executed when any user views the affected page in their browser. No special authentication or network positioning is required beyond basic application access. An attacker can achieve account takeover, session hijacking, or perform actions in the context of the victim's authenticated session. Users should upgrade to patched versions when available.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed: CVE-2026-27244 published

References