Executive brief
Adobe Experience Manager, a content management and digital asset platform used by enterprises to manage web and mobile experiences, contains a stored cross-site scripting (XSS) vulnerability in form field handling. A low-privileged attacker can inject malicious scripts into form fields that execute when other users browse the affected pages, potentially leading to session hijacking, credential theft, or malware distribution.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw affecting Adobe Experience Manager's form field processing. A low-privileged authenticated attacker can inject malicious JavaScript code into vulnerable form fields; the injected script is persisted server-side and executes in the browsers of users who view the affected content. The scope change indicates an increase in attack impact beyond the original component. No indication of a patch availability is present in the advisory.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed