Junglewise Threat Intelligence

CVE-2026-47950: Adobe Experience Manager stored XSS in form fields

CVE-2026-47950 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security flaw. An attacker with basic user access can submit malicious code into website forms, which then runs in the browsers of other users or administrators who view that content. This could lead to unauthorized actions being performed on behalf of legitimate users or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw resides in certain form fields that fail to adequately sanitize user-supplied data before storing it and rendering it back to users. An authenticated, low-privileged attacker can exploit this by submitting a crafted payload via the network. When a victim (such as an administrator) views the page where this data is displayed, the malicious script executes in their browser context. This vulnerability has a changed scope (S:C), meaning the impact can extend beyond the AEM application itself to the victim's browser environment. Adobe has addressed this in updated versions of AEM.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References