Executive brief
Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security flaw. An attacker with basic user permissions can save malicious scripts into website forms. When other users or administrators view these pages, the scripts run automatically in their browsers, potentially allowing the attacker to steal session information or perform unauthorized actions on their behalf.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw is located within certain form fields that fail to adequately sanitize user-supplied data before storage. An attacker with low-privileged access can submit a crafted payload containing malicious JavaScript. When an unsuspecting user, such as an administrator, navigates to the page where this data is rendered, the script executes within the context of their browser session. This can lead to session hijacking or unauthorized data access. The vulnerability affects versions 6.5.24, LTS SP1, 2026.04 and earlier.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed: Initial publication of the vulnerability advisory.
- 2026-06-09: advisory: Adobe released security bulletin APSB26-56.