Junglewise Threat Intelligence

CVE-2026-47936: Adobe Experience Manager stored XSS in form fields

CVE-2026-47936 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and websites, is affected by a security flaw that allows unauthorized script injection. An attacker with low-level access can place malicious code into website forms, which then executes in the browsers of other users, such as administrators or site visitors. This could lead to the theft of login tokens, unauthorized actions performed on behalf of users, or the defacement of web content.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager due to improper neutralization of input during web page generation (CWE-79). The flaw is located within certain form fields that fail to adequately sanitize user-supplied data before storage and subsequent display. An authenticated, low-privileged attacker can exploit this by submitting a specially crafted payload through these fields. When a victim (such as an administrator) views the page where this data is rendered, the malicious JavaScript executes within the context of their session. This vulnerability has a 'Changed' scope (S:C), meaning the impact can extend beyond the vulnerable component to other parts of the user's browser environment. Adobe has addressed this in security bulletin APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References