Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability in its form fields. An attacker with basic user access can save malicious scripts into the system that will run in the browsers of other users, such as administrators, when they view the affected pages. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input in certain form fields (CWE-79). A remote attacker with low-level privileges can inject malicious JavaScript into these fields, which is then persisted on the server. The payload executes in the context of any user who subsequently navigates to the page containing the vulnerable field. This exploit requires user interaction (viewing the page) and has a changed scope (S:C), meaning the script can impact components beyond the vulnerable form itself. Adobe has addressed this in security bulletin APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory