Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and websites, is affected by a security flaw that allows unauthorized script injection. An attacker with basic user permissions can insert malicious code into website forms, which then runs in the browsers of other users or administrators who view those pages. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input in form fields (CWE-79). A remote attacker with low-privileged credentials can submit malicious JavaScript that is permanently stored on the server. When a victim, such as an administrator, navigates to the affected page, the script executes within the context of their browser session. This vulnerability has a 'Changed' scope (S:C), meaning the impact can extend beyond the AEM application itself to other integrated web components. Adobe has addressed this in security bulletin APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory