Junglewise Threat Intelligence

CVE-2026-47949: Adobe Experience Manager stored XSS in form fields

CVE-2026-47949 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used for managing digital content and customer experiences, is affected by a security flaw that allows unauthorized script injection. An attacker with low-level access can place malicious code into form fields that then runs in the browsers of other users, such as administrators, who view those pages. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager due to improper neutralization of input during web page generation. A remote attacker with low-privileged credentials can exploit this by submitting malicious JavaScript into vulnerable form fields. When a victim (typically an administrator or another user) navigates to the page where this input is rendered, the script executes within the context of the victim's browser session. This vulnerability has a CVSS score of 5.4, noting that the scope is changed (S:C), which often implies the script can impact components beyond the immediate vulnerable field. Users are advised to update to the latest versions as specified in Adobe advisory APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References