Executive brief
Adobe Experience Manager, a platform used for managing digital content and customer experiences, is affected by a security flaw that allows users with low-level access to inject malicious scripts into website forms. If a victim, such as an administrator or another user, views the page where this script was saved, the malicious code will run in their browser. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager due to improper neutralization of input in certain form fields (CWE-79). An attacker with low-privileged credentials can submit malicious JavaScript that is then permanently stored on the server. When a victim navigates to the affected page, the script executes within the context of the victim's browser session. This vulnerability has a changed scope (S:C), meaning the impact can extend beyond the vulnerable component to other parts of the application environment. The attack requires network access and minimal user interaction (viewing the page).
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: advisory: Initial disclosure by Adobe and NVD publication.