Executive brief
Adobe Experience Manager, a widely-used digital content management platform, contains a stored cross-site scripting vulnerability in its form field handling. An attacker with low-level user access can inject malicious scripts that execute in other users' browsers when they view the affected page, potentially leading to account compromise or data theft.
Technical details
This is a stored (persistent) cross-site scripting vulnerability in Adobe Experience Manager's form field components. The vulnerability allows a low-privileged authenticated user to inject malicious JavaScript into form fields; the injected payload is stored server-side and executed in victims' browsers when they access the affected page. The scope classification indicates this crosses privilege or security boundary. No evidence of exploitation in the wild has been reported. A patch is expected from Adobe's APSB26-98 security bulletin.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed