Junglewise Threat Intelligence

CVE-2026-47951: Adobe Experience Manager stored XSS in form fields

CVE-2026-47951 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security flaw that allows unauthorized script injection. An attacker with low-level access can insert malicious code into form fields that will then run in the browsers of other users, including administrators, who view those pages. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

This vulnerability is a stored Cross-Site Scripting (XSS) issue (CWE-79) residing in certain form fields within Adobe Experience Manager. A remote attacker with low-privileged credentials can submit specially crafted input containing malicious JavaScript, which is then permanently stored on the server. When other users navigate to the affected page, the script executes within the context of their browser session. Because the CVSS score indicates a 'Scope Change' (S:C), the script may be able to interact with or impact resources beyond the immediate vulnerable component. Adobe has addressed this in security bulletin APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe security bulletin APSB26-56 published

References