Executive brief
Adobe Experience Manager, a widely-used content management platform, contains a stored cross-site scripting vulnerability in form field handling. A low-privileged attacker can inject malicious JavaScript into form fields that executes in the browsers of other users when they view the affected pages, potentially enabling session hijacking, credential theft, or defacement of content.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager's form field handling. The vulnerability allows a low-privileged attacker to inject malicious JavaScript into form fields; the injected script persists in the application and executes in the browsers of victims who view the affected content. Attack requires authentication but no special privileges beyond standard user access. An attacker can execute arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking, credential theft, or unauthorized actions. A patch is expected from Adobe (APSB26-98).
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed