Executive brief
Adobe Experience Manager, a content management system used by enterprises to build and manage websites and digital experiences, contains a stored cross-site scripting (XSS) vulnerability in form field handling. A low-privileged attacker can inject malicious code into form fields that gets executed in the browsers of legitimate users, potentially allowing account takeover, credential theft, or malware distribution to site visitors.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Experience Manager versions 6.5.23 and earlier, affecting form field input validation or output encoding. An attacker with low-level privileges can inject malicious JavaScript into vulnerable form fields; the payload persists in the application and executes in the browser context of any user who views the affected page. This requires no user interaction beyond the attacker having valid low-privileged account access. The attacker can achieve arbitrary actions in the context of the victim's browser session, including session hijacking or data exfiltration. Patches are expected from Adobe but are not yet available in public advisories.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed