Executive brief
Adobe Experience Manager, an enterprise content management system used by organizations to build and manage websites and digital content, is vulnerable to stored cross-site scripting (XSS) attacks. A low-privileged attacker can inject malicious scripts into vulnerable form fields; when other users view the affected content, the scripts execute in their browsers, potentially allowing attackers to steal session tokens, capture credentials, or perform actions on behalf of victims.
Technical details
This is a stored XSS vulnerability in Adobe Experience Manager affecting form field handling. The root cause is insufficient input validation and output encoding on form fields that persist user-supplied data. A low-privileged attacker can inject malicious JavaScript that is stored in the application and executed in the browser of any user who views the affected form. The attack requires the attacker to have write access to form fields (low privilege context) but does not require victim interaction beyond viewing the page. No patch availability is mentioned in the advisory.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-16: disclosed