Junglewise Threat Intelligence

CVE-2026-27255: Adobe Experience Manager stored XSS in form fields

CVE-2026-27255 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely used content management and digital asset platform, contains a stored cross-site scripting vulnerability in form handling that allows low-privileged users to inject malicious scripts. An attacker could craft malicious content that executes in the browsers of other users viewing the compromised pages, potentially leading to account compromise, credential theft, or unauthorized actions taken on behalf of legitimate users.

Technical details

This is a stored XSS vulnerability in Adobe Experience Manager versions 6.5.23 and earlier, where malicious scripts can be injected into vulnerable form fields. The vulnerability requires low privilege access to inject the payload, but no further user interaction is needed beyond the victim visiting the page containing the stored payload. When a user browses to a page with the vulnerable form field, the malicious JavaScript is automatically executed in their browser within the context of the application, allowing attackers to steal session cookies, perform actions as the victim, or redirect users to phishing sites. Patches are available from Adobe.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References