Executive brief
Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security flaw. An attacker with basic user permissions can insert malicious code into certain website forms. If another user, such as an administrator, views the page where this code was submitted, the malicious script will run in their browser, potentially allowing the attacker to perform unauthorized actions or steal session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input in specific form fields (CWE-79). A remote attacker with low-level privileges can submit malicious JavaScript that is permanently stored on the server. When a victim (typically an administrator or another user) navigates to the page where this input is rendered, the script executes within the context of the victim's browser session. This vulnerability has a CVSS score of 5.4, noting that the 'Scope' is changed, which often implies the script can impact components beyond the immediate vulnerable field. Users are advised to update to the latest patched versions provided by Adobe.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory