Executive brief
Adobe Experience Manager, a widely-used content management platform, contains a stored cross-site scripting (XSS) vulnerability in form field handling. A low-privileged attacker can inject malicious scripts that persist in the system and execute in the browsers of other users who view affected pages, potentially compromising user sessions, stealing credentials, or redirecting users to malicious sites.
Technical details
This is a stored (persistent) XSS vulnerability in Adobe Experience Manager's form field processing, where user-supplied input is not properly sanitized before being stored and later rendered in web pages. A low-privileged authenticated attacker can inject malicious JavaScript into vulnerable form fields; the payload persists in the application and executes in the browsers of subsequent users who access the affected content. The vulnerability changes scope, meaning an attacker may be able to impact components or data beyond the directly targeted form field. No patch availability information is available from the provided advisory text.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed