Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security flaw in its web forms. An attacker with basic user permissions can insert malicious code into form fields that will then run in the browsers of other users, such as administrators, who view those pages. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager due to improper neutralization of input in form fields. An authenticated, low-privileged attacker can inject malicious JavaScript into these fields, which is then persisted on the server. When another user (the victim) navigates to the affected page, the script executes within the context of their browser session. Because the CVSS score indicates a scope change (S:C), the script may be able to interact with or impact components beyond the immediate vulnerable application. The vulnerability affects versions 6.5.24, LTS SP1, 2026.04 and earlier.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory