Executive brief
Adobe Experience Manager, a widely-used content management and digital asset platform, contains a stored cross-site scripting (XSS) flaw in form field handling. A low-privileged attacker can inject malicious scripts that execute in other users' browsers, potentially leading to credential theft, session hijacking, or unauthorized actions performed on behalf of victims.
Technical details
The vulnerability is a stored XSS in Adobe Experience Manager's form field processing, allowing a low-privileged authenticated attacker to inject malicious JavaScript that persists in the application. The injected script executes in the browsers of any user (including administrators) who view the affected form field, changing the security scope of the vulnerability. An attacker with low privilege access can craft a malicious payload, store it in a vulnerable form field, and any subsequent viewer becomes vulnerable to script execution in their security context.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed