Junglewise Threat Intelligence

CVE-2026-47966: Adobe Experience Manager stored XSS in form fields

CVE-2026-47966 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and customer experiences, is affected by a security flaw. An attacker with low-level access can inject malicious scripts into certain form fields. If another user, such as an administrator, views the affected page, the script could execute in their browser, potentially allowing the attacker to perform unauthorized actions or access sensitive information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). A low-privileged attacker can exploit this by injecting malicious scripts into vulnerable form fields. The attack requires network access and a victim to interact with the page where the script is stored. Because the vulnerability is 'stored', the payload remains on the server and executes in the context of any user who views the compromised component. The CVSS score of 5.4 reflects a changed scope, meaning the exploit can impact components beyond the vulnerable AEM field itself.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References