Junglewise Threat Intelligence

CVE-2026-47941: Adobe Experience Manager stored XSS in form fields

CVE-2026-47941 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability in its form fields. An attacker with basic user access can save malicious scripts into these forms, which then run automatically in the browsers of other users or administrators who view the page. This could lead to unauthorized actions being performed on behalf of legitimate users or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw is caused by improper neutralization of input during web page generation (CWE-79) within certain form fields. A remote attacker with low-level privileges can inject malicious JavaScript that is persistently stored on the server. When a victim navigates to the affected page, the script executes in the context of the victim's browser session. This vulnerability has a changed scope (S:C), meaning the impact can extend beyond the AEM component itself to the user's browser environment. Adobe has released security updates to address this issue.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References