Junglewise Threat Intelligence

CVE-2026-47978: Adobe Experience Manager stored XSS in form fields

CVE-2026-47978 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used for managing digital content and customer experiences, is affected by a security flaw that allows unauthorized script injection. An attacker with low-level access can place malicious code into form fields that then runs in the browsers of other users, including administrators, who view those pages. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw is located within certain form fields that fail to adequately sanitize user-supplied data before storage and subsequent display. An attacker with low-privileged credentials can submit a malicious payload via a network request; when a victim (such as an administrator) views the affected page, the script executes in their browser context. Because the CVSS score indicates a 'Scope Change' (S:C), the script may be able to interact with or access data from other parts of the application beyond the immediate vulnerable component. Adobe has addressed this in security bulletin APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References