Junglewise Threat Intelligence

CVE-2026-27249: Adobe Experience Manager stored XSS in form fields

CVE-2026-27249 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management and digital asset platform used by enterprises to build and manage web properties, is vulnerable to stored cross-site scripting (XSS) in form fields. A low-privileged attacker can inject malicious scripts that execute in the browsers of legitimate users who view the affected pages, potentially leading to session hijacking, credential theft, or further compromise of the web application.

Technical details

Adobe Experience Manager versions 6.5.23 and earlier contain a stored XSS vulnerability in form field handling. The vulnerability allows low-privileged attackers to inject malicious JavaScript into form fields without proper output encoding or sanitization. When a victim visits a page containing the injected payload, the malicious script executes in their browser with the privileges of the authenticated session. No patch information is currently available in the advisory; administrators should monitor Adobe's security bulletins for guidance.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References