Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and website assets, is affected by a security flaw in its web forms. An attacker with basic user access can plant malicious code into certain form fields that will then run in the browsers of other users, such as administrators, who view those pages. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw is located within certain form fields, where a low-privileged attacker can inject malicious JavaScript. This script is persistently stored on the server and executes in the context of any user who subsequently views the affected page. Exploitation requires network access and low-level authentication, but relies on a victim interacting with the page (User Interaction: Required). Because the security scope is changed (S:C), the script can potentially access data or perform actions outside the immediate environment of the vulnerable component. Adobe has addressed this in security bulletin APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24 and earlier, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory