Executive brief
Adobe Experience Manager, a platform used for managing digital content and customer experiences, is affected by a security flaw that allows attackers to inject malicious scripts into website forms. An attacker with low-level access could use this to target other users, including administrators, potentially leading to unauthorized actions or data theft when the victim views the affected page. This could compromise the integrity of the website and the security of its visitors' sessions.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager due to improper neutralization of input in certain form fields (CWE-79). A remote attacker with low-privileged credentials can submit malicious JavaScript that is persistently stored on the server. When a victim (such as an administrator) navigates to the page containing the injected content, the script executes in the context of their browser session. This vulnerability has a CVSS score of 5.4, noting that the 'Scope' is changed (S:C), which typically implies the script can impact components beyond the immediate vulnerable field. Users are advised to update to the latest patched versions as specified in Adobe advisory APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory