Junglewise Threat Intelligence

CVE-2026-47939: Adobe Experience Manager stored XSS in form fields

CVE-2026-47939 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability in its web forms. An attacker with basic user access can insert malicious code into form fields that will then run in the browsers of other users, such as administrators, who view that content. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager due to improper neutralization of input in form fields (CWE-79). A remote attacker with low-level privileges can submit malicious scripts that are persistently stored on the server. When an unsuspecting user or administrator views the page containing the injected content, the script executes within the context of their browser session. This vulnerability has a 'Changed' scope (S:C), meaning the impact can extend beyond the vulnerable component to other parts of the web environment. Adobe has addressed this in security bulletin APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: advisory: Initial disclosure by Adobe and NVD publication

References