Junglewise Threat Intelligence

CVE-2026-47957: Adobe Experience Manager stored XSS in form fields

CVE-2026-47957 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security flaw. An attacker with basic user access can save malicious scripts into website forms, which then run automatically in the browsers of other users or administrators who view those pages. This could lead to unauthorized actions being performed on behalf of legitimate users or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager due to improper neutralization of input during web page generation (CWE-79). The flaw is located within certain form fields, allowing a low-privileged attacker to inject arbitrary JavaScript. This script is persistently stored on the server and executes in the context of a victim's browser session when they navigate to the affected page. The attack requires network access and minimal user interaction (viewing the page). Adobe has addressed this in security bulletin APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References