Executive brief
Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security flaw. An attacker with basic user permissions can save malicious code into certain website forms. If another user or administrator views the page where this code was saved, the malicious script will run in their browser, potentially allowing the attacker to perform unauthorized actions or steal session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). A low-privileged attacker can inject malicious JavaScript into vulnerable form fields, which is then stored on the server. The attack requires a victim to navigate to the page containing the injected script, at which point the payload executes in the context of the victim's browser session. This vulnerability has a CVSS score of 5.4, reflecting that while it requires low privileges and user interaction, the security scope is changed. Users are advised to update to the latest patched versions as specified in Adobe advisory APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory