Executive brief
Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security flaw. An attacker with basic user access can inject malicious scripts into website forms. If another user or administrator views the affected page, the script could run in their browser, potentially allowing the attacker to perform unauthorized actions or steal session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager due to improper neutralization of input during web page generation (CWE-79). A remote attacker with low-level privileges can submit malicious JavaScript into vulnerable form fields. This script is then stored on the server and executed in the context of other users' browsers when they navigate to the affected page. The vulnerability has a CVSS score of 5.4, reflecting that while it requires user interaction and authentication, the security scope is changed, potentially impacting other components. Adobe has addressed this in security bulletin APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory