Junglewise Threat Intelligence

CVE-2026-48299: Adobe Experience Manager stored XSS in form fields

CVE-2026-48299 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security flaw that allows unauthorized script injection. An attacker with low-level access can place malicious code into form fields that will later execute in the browsers of other users, such as administrators. This could lead to the theft of session cookies, unauthorized actions performed on behalf of other users, or the defacement of internal web pages.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw is located within certain form fields that fail to adequately sanitize user-supplied data before storage and subsequent display. An attacker with low-privileged authenticated access can inject malicious JavaScript payloads into these fields. When a victim (such as an administrator) views the page containing the injected content, the script executes in their browser context. The vulnerability has a CVSS score of 5.4, noting that the 'Scope' is changed (S:C), which typically indicates the script can impact components beyond the immediate security scope of the vulnerable application.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References