Executive brief
Adobe Experience Manager, a widely-used content management and digital experience platform, contains a stored cross-site scripting (XSS) vulnerability in form field handling. A low-privileged attacker can inject malicious scripts that persist in the system and execute in victims' browsers, potentially allowing credential theft, session hijacking, or unauthorized actions performed on behalf of the victim.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager versions 6.5.23 and earlier, affecting form field input validation. The vulnerability allows a low-privileged attacker to inject malicious JavaScript into form fields; this payload is stored server-side and executed in the browser of any user viewing the compromised page. No user interaction beyond browsing to the affected page is required to trigger the vulnerability. An attacker with low privileges can inject arbitrary scripts that execute in victims' browsers with the victim's privileges and session context. The vulnerability was disclosed on 2026-03-11; patch status is not confirmed from available sources.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed