Junglewise Threat Intelligence

CVE-2026-27254: Adobe Experience Manager stored XSS in form fields

CVE-2026-27254 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager is a content management system used by enterprises to create and manage digital experiences. A stored cross-site scripting (XSS) vulnerability in form fields allows a low-privileged attacker to inject malicious scripts that execute in other users' browsers, potentially leading to account compromise, session hijacking, or data theft when victims view affected pages.

Technical details

A stored XSS vulnerability exists in Adobe Experience Manager 6.5.23 and earlier, where user input in form fields is not properly sanitized before being stored and rendered. An attacker with low privileges can inject malicious JavaScript into vulnerable form fields; the payload is persisted in the application and executed in the context of any user's browser that views the compromised page. This allows an attacker to steal session cookies, perform actions on behalf of victims, or redirect users to phishing sites. Adobe has released patches in security bulletin APSB26-24.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References