Executive brief
Adobe Experience Manager, a widely-used platform for managing digital content and web experiences, contains a stored cross-site scripting (XSS) vulnerability in form field handling. A low-privileged user could inject malicious scripts into forms, which would execute in the browser of any user who views the affected page, potentially allowing account takeover, session hijacking, or data theft without the victim's knowledge.
Technical details
This is a stored XSS vulnerability affecting Adobe Experience Manager versions 6.5.23 and earlier, where user input in form fields is not properly sanitized before being stored and displayed to other users. The vulnerability requires low-privilege account access to inject the malicious payload into a form field, but no further user interaction is needed to trigger the exploit—the script executes automatically when any user views the compromised page. An attacker with low-privilege credentials can achieve arbitrary JavaScript execution in the context of victims' browsers, potentially leading to session hijacking, credential theft, or further system compromise. Patch availability was indicated in the advisory reference (APSB26-24), though the full advisory content was not accessible.
Affected products
- Adobe Experience Manager 6.5.23 and earlier
Timeline
- 2026-03-11: disclosed: Public disclosure via NVD
- 2026-03-11: advisory: Adobe APSB26-24 advisory issued