Executive brief
Adobe Experience Manager, a platform used for managing digital content and websites, is affected by a security flaw that allows users with low-level access to inject malicious scripts into web forms. When other users or administrators view the affected pages, these scripts can execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager due to improper neutralization of input during web page generation. An attacker with low-privileged credentials can submit malicious JavaScript through vulnerable form fields, which is then permanently stored on the server. When a victim navigates to the page where this input is rendered, the script executes in the context of the victim's browser session. The vulnerability has a CVSS score of 5.4, reflecting that while it requires user interaction and low privileges, the 'Scope' is changed, potentially impacting other components. Patches are available in versions 2026.6.0 (Cloud Service), 6.5.25, and 6.5 LTS SP2.
Affected products
- Adobe Experience Manager as a Cloud Service <= 2026.5.0
- Adobe Experience Manager 6.5 LTS <= SP1
- Adobe Experience Manager 6.5 <= 6.5.24
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory