Junglewise Threat Intelligence

CVE-2026-47948: Adobe Experience Manager stored XSS in form fields

CVE-2026-47948 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security flaw that allows unauthorized script injection. An attacker with basic user permissions can save malicious code into website forms, which then runs automatically in the browsers of other users or administrators who view those pages. This could lead to the theft of login session information or unauthorized actions being performed on behalf of the victim.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). A low-privileged attacker can exploit this by submitting malicious scripts into vulnerable form fields, which are then stored on the server. When a victim (such as an administrator) navigates to the page where this data is rendered, the script executes within the context of the victim's browser session. This vulnerability has a CVSS score of 5.4, reflecting that while it requires low privileges and user interaction, the 'Scope' is changed, potentially impacting other components. Users are advised to update to the latest versions as specified in Adobe advisory APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References