Junglewise Threat Intelligence

CVE-2026-47980: Adobe Experience Manager stored XSS in form fields

CVE-2026-47980 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and customer experiences, is affected by a security flaw that allows unauthorized script injection. An attacker with low-level access can place malicious code into website forms, which then executes in the browsers of other users, such as administrators or customers. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw is located within certain form fields that fail to adequately sanitize user-supplied data before storage and subsequent display. An authenticated, low-privileged attacker can exploit this by submitting a malicious payload via a network request. When a victim (typically an administrator or another user) views the page containing the injected script, the payload executes within the context of their browser session. This vulnerability has a CVSS score of 5.4, noting that while it requires user interaction and authentication, the security scope is changed.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: advisory: Adobe published security bulletin APSB26-56
  • 2026-06-09: disclosed

References