Executive brief
Adobe Experience Manager, a widely-used platform for managing digital content and customer experiences, contains a vulnerability that allows low-privileged users to inject malicious code into web forms. When legitimate users view pages containing these injected scripts, the malicious code executes in their browsers, potentially compromising their accounts, stealing session data, or defacing content they see.
Technical details
This is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager's form field handling. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; the payload persists in the application's database and executes in the browsers of any users who view the affected page. The vulnerability changes the scope of what an attacker can access or modify. No patch status is available from the provided advisory; however, Adobe security bulletin APSB26-98 should be consulted for remediation details and updates.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed