Junglewise Threat Intelligence

CVE-2026-47954: Adobe Experience Manager stored XSS in form fields

CVE-2026-47954 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security vulnerability. An attacker with low-level access can inject malicious scripts into certain form fields. If another user, such as an administrator, views the affected page, the script could execute in their browser, potentially allowing the attacker to perform unauthorized actions or access sensitive information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input in specific form fields (CWE-79). A remote attacker with low-privileged credentials can submit malicious JavaScript that is permanently stored on the server. When a victim, such as a site administrator, navigates to the page where this data is rendered, the script executes within the context of the victim's browser session. This vulnerability has a CVSS score of 5.4, reflecting that while it requires user interaction and authentication, the security scope is changed, potentially impacting other components of the web application. Users are advised to update to the latest versions as specified in Adobe's security bulletin APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References