Executive brief
Adobe Experience Manager, a content management system used by enterprises to create and manage digital experiences, contains a stored cross-site scripting vulnerability in form field handling. A low-privileged attacker can inject malicious scripts that execute in the browsers of other users who view the affected page, potentially leading to session hijacking, credential theft, or defacement.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw affecting form field validation or output encoding in Adobe Experience Manager. A low-privileged authenticated attacker can inject malicious JavaScript into vulnerable form fields; the payload persists in the application's database and executes in the browsers of subsequent users who access the affected content. The scope change indicates this may escalate privileges or affect other users beyond the attacker. The attack requires prior authentication but does not require user interaction beyond normal browsing of the affected page.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed