Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and websites, is affected by a security flaw in its web forms. An attacker with basic user permissions can insert malicious code into form fields that will later run in the browsers of other users, such as administrators. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager due to improper neutralization of input in certain form fields. A remote attacker with low-level privileges can submit malicious scripts that are persistently stored on the server. When an unsuspecting user, such as an administrator, views the page containing the injected content, the script executes within the context of their browser session. This vulnerability has a CVSS score of 5.4, noting that while it requires user interaction and low privileges, the 'Scope' is changed, potentially allowing the attacker to impact other components of the application. Users are advised to update to the latest versions as specified in Adobe advisory APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory