Executive brief
Adobe Experience Manager, a widely-used content management platform, is vulnerable to stored cross-site scripting (XSS) in form fields. A low-privileged attacker can inject malicious scripts that execute in victims' browsers when they access affected pages, potentially compromising user sessions, stealing credentials, or defacing content.
Technical details
This vulnerability is a stored XSS issue affecting Adobe Experience Manager's form field handling. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; the payload persists server-side and is executed in the browser of any user viewing the affected page. The attack requires the attacker to have some level of access to the application (low-privilege user). The scope is changed, indicating the vulnerability may affect confidentiality, integrity, or availability of the system beyond just the vulnerable component. Adobe has issued patch APSB26-98; users should consult Adobe's security advisory for affected versions and updates.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: APSB26-98