Junglewise Threat Intelligence

CVE-2026-47977: Adobe Experience Manager stored XSS in form fields

CVE-2026-47977 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and websites, is affected by a security flaw in its form fields. An attacker with basic user access could save malicious scripts into these forms, which then run automatically in the browsers of other users or administrators who view the page. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). A low-privileged attacker can inject malicious JavaScript into vulnerable form fields, which is then stored on the server. The payload executes in the context of any user who subsequently views the affected page. This attack requires network access and basic authentication, along with minimal user interaction (the victim browsing to the page). The vulnerability has a changed scope (S:C), meaning the impact can extend beyond the AEM application to the user's browser environment. Adobe has addressed this in APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: advisory: Initial disclosure by Adobe and NVD publication.

References