Junglewise Threat Intelligence

CVE-2026-47953: Adobe Experience Manager stored XSS in form fields

CVE-2026-47953 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and websites, is affected by a security flaw that allows unauthorized script injection. An attacker with basic user permissions can insert malicious code into website forms, which then executes in the browsers of other users or administrators who view those pages. This could lead to the theft of login tokens, unauthorized actions performed on behalf of users, or the defacement of web content.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input in certain form fields (CWE-79). A remote attacker with low-level privileges can submit malicious JavaScript that is persistently stored on the server. When a victim, such as an administrator, navigates to the affected page, the script executes within the context of their browser session. The vulnerability has a CVSS score of 5.4, reflecting that while it requires user interaction and authentication, the 'Scope' is changed, potentially allowing the attacker to access data or perform actions beyond the immediate vulnerable component. Users are advised to update to the latest patched versions as specified in Adobe advisory APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References