Junglewise Threat Intelligence

CVE-2026-47990: Adobe Experience Manager stored XSS in form fields

CVE-2026-47990 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security flaw. An attacker with basic user permissions can insert malicious code into certain website forms. If another user or administrator views the page where this code was saved, the malicious script will run in their browser, potentially allowing the attacker to perform unauthorized actions or steal session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager due to improper neutralization of input during web page generation (CWE-79). A low-privileged attacker can exploit this by injecting malicious JavaScript into vulnerable form fields. Because the payload is stored on the server, the script executes in the context of any user who subsequently views the affected page. This attack requires network access and minimal user interaction (viewing the page). The vulnerability has been assigned a CVSS score of 5.4, noting that the security scope is changed, which often implies the ability to impact components beyond the immediate vulnerable application.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References