Junglewise Threat Intelligence

CVE-2026-27265: Adobe Experience Manager stored XSS in form fields

CVE-2026-27265 · Severity: medium · CVSS 5.4 · Published 2026-03-11

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform for building websites and digital experiences, contains a stored cross-site scripting vulnerability in form field handling. An attacker with low privileges could inject malicious scripts that execute when legitimate users view affected pages, potentially allowing credential theft, session hijacking, or defacement of user-facing content.

Technical details

The vulnerability is a stored XSS (CWE-79) affecting Adobe Experience Manager versions 6.5.23 and earlier, caused by insufficient input validation or output encoding in form field processing. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; the payload persists in the application and executes in the browser of any user who visits the affected page. The attack requires network access to the AEM instance but does not require additional authentication beyond the ability to submit form data. Successful exploitation allows arbitrary JavaScript execution in victim browsers within the context of the AEM application, enabling session theft or account compromise. Patches are available in Adobe Security Bulletin APSB26-24.

Affected products

  • Adobe Experience Manager 6.5.23 and earlier

Timeline

  • 2026-03-11: disclosed

References