Executive brief
Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security flaw that allows unauthorized script injection. An attacker with low-level access can insert malicious code into website forms, which then executes in the browsers of other users or administrators who view those pages. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw is located within certain form fields that fail to adequately sanitize user-supplied data before storage and subsequent display. An authenticated attacker with low-level privileges can exploit this by submitting a specially crafted payload through a network request. When a victim (such as an administrator) navigates to the page where the malicious input is rendered, the script executes within the context of the victim's browser session. This vulnerability has a 'Changed' scope (S:C), meaning the impact can extend beyond the AEM component to other parts of the user's environment. Adobe has addressed this in security bulletin APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-56 published.