Junglewise Threat Intelligence

CVE-2026-47975: Adobe Experience Manager stored XSS in form fields

CVE-2026-47975 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability in its form fields. An attacker with basic user access can plant malicious scripts that trigger when other users or administrators view specific pages. This could lead to unauthorized actions being performed in the victim's browser, potentially compromising user sessions or sensitive information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw is caused by improper neutralization of input during web page generation (CWE-79) within certain form fields. An authenticated, low-privileged attacker can inject malicious JavaScript that is permanently stored on the server. When a victim navigates to the affected page, the script executes in the context of the victim's browser session. This vulnerability has a CVSS score of 5.4, reflecting that while it requires user interaction and authentication, the scope is changed, potentially impacting other components.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References