Executive brief
Adobe Experience Manager, a widely-used content management platform for building websites and digital experiences, contains a stored cross-site scripting (XSS) flaw in form fields. A low-privileged user can inject malicious scripts that execute in other users' browsers when they view affected pages, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of victims.
Technical details
This is a stored XSS vulnerability in Adobe Experience Manager's form handling logic. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields, which is then persisted and executed in the browsers of any user who views the affected page. The vulnerability has a changed scope, meaning the impact extends beyond the original security context. The flaw is reachable by authenticated users with limited privileges and does not require special preconditions beyond the ability to submit form data.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed