Executive brief
Adobe Experience Manager, a widely-used content management and digital asset platform, contains a stored cross-site scripting (XSS) vulnerability in form field handling. A low-privileged user can inject malicious scripts that execute in other users' browsers when they view the affected page, potentially allowing session hijacking, credential theft, or unauthorized actions on behalf of the victim.
Technical details
The vulnerability is a stored XSS flaw affecting form field validation or sanitization in Adobe Experience Manager. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; the payload persists in the application and is executed in victims' browsers without proper output encoding when the page is accessed. This changes the scope of impact, meaning the vulnerability can affect users with higher privileges or broader system access than the attacker. No preconditions beyond low-privilege authentication are required. Patches are expected from Adobe via APSB26-98.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed