Junglewise Threat Intelligence

CVE-2026-48355: Adobe Experience Manager stored XSS in form fields

CVE-2026-48355 · Severity: medium · CVSS 5.4 · Published 2026-07-14

Technologies: Adobe Experience Manager as a Cloud Service. Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage and deliver digital content and assets, is affected by a security flaw that allows users with low-level access to inject malicious code into website forms. If a victim, such as a site administrator or another user, views the page where this code was saved, the malicious script will run in their web browser. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager due to improper neutralization of input during web page generation (CWE-79). An attacker with low-privileged credentials can submit malicious JavaScript into vulnerable form fields, which is then stored on the server. When a victim subsequently views the affected page, the script executes within the context of the victim's browser session. The vulnerability has a CVSS score of 5.4, reflecting that while it requires user interaction and low privileges, the impact scope is changed. Patches are available in versions 2026.6.0 (Cloud Service), 6.5.25 (On-premise), and SP2 (LTS).

Affected products

  • Adobe Experience Manager as a Cloud Service <= 2026.5.0
  • Adobe Experience Manager 6.5 LTS <= SP1
  • Adobe Experience Manager 6.5 <= 6.5.24

Timeline

  • 2026-07-14: advisory: Adobe published security bulletin APSB26-74
  • 2026-07-14: disclosed

References

Related threats