Executive brief
Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security flaw in its web forms. An attacker with basic user access can insert malicious code into these forms, which then runs automatically in the browsers of other users or administrators who view the page. This could lead to unauthorized actions being performed on behalf of legitimate users or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw is located within certain form fields that fail to adequately sanitize user-supplied data before storage and subsequent display. An attacker with low-privileged credentials can submit a malicious payload via the network; when a victim (such as an administrator) views the affected page, the script executes in their browser context. This vulnerability has a CVSS score of 5.4, noting that while it requires user interaction, the security scope is changed, potentially allowing access to cookies or session tokens. Users are advised to update to the latest patched versions as specified in Adobe advisory APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory