Executive brief
Adobe Experience Manager, a widely used content management and digital asset platform, contains a stored cross-site scripting (XSS) vulnerability in form fields that allows low-privileged users to inject malicious scripts. When a victim accesses a page containing an affected form field, the injected script executes in their browser, potentially leading to session hijacking, credential theft, or malware distribution.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Experience Manager's form field handling, where user-supplied input is not properly sanitized before being stored and displayed. A low-privileged attacker can inject arbitrary JavaScript into vulnerable form fields. The malicious script persists in the application's database and executes in the browsers of any user who views the affected page, requiring no authentication bypass or complex preconditions. An attacker can achieve account takeover, data exfiltration, or unauthorized actions on behalf of victims. Patch availability should be confirmed via the official Adobe security advisory.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed