Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and websites, is affected by a security flaw that allows attackers to inject malicious scripts into web forms. An attacker with low-level access could use this to target other users, including administrators, potentially leading to unauthorized actions or the theft of sensitive session information when the victim views the affected page. This could compromise the integrity of the website's content and user data.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input in certain form fields (CWE-79). A remote attacker with low-privileged credentials can submit malicious JavaScript that is then stored on the server. When a victim, such as an administrator, navigates to the page where this data is rendered, the script executes within the context of the victim's browser session. The vulnerability has a CVSS score of 5.4, noting that the 'Scope' is changed (S:C), which often implies the script can impact components beyond the immediate vulnerable application. Users are advised to update to the latest versions as specified in Adobe advisory APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: advisory: Adobe published security bulletin APSB26-56
- 2026-06-09: disclosed: CVE-2026-47942 published to the NVD