Description
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-06-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier contain a stored Cross‑Site Scripting vulnerability (CWE‑79). A low‑privileged attacker can inject malicious JavaScript into form fields that are later rendered to users. When a victim opens the page containing the vulnerable field, the script executes in the victim's browser, potentially allowing the attacker to hijack sessions, steal credentials or deface the site. The vulnerability is considered stored because the malicious code is preserved in the system and served to all users who view the affected page.

Affected Systems

Adobe Experience Manager product line, including all installations running version 6.5.24, the LTS Service Pack 1, the 2026.04 release, and any earlier releases of these versions.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score is currently not available. The vulnerability is not listed in the CISA KEV catalog. An attacker with limited privileges, possibly merely an authenticated content contributor, can exploit this flaw by submitting malicious input through a form field, thereby having the script stored and served to other users. Execution occurs in the victim's browser, so the impact is confined to the end‑user environment, but the ability to execute arbitrary code can lead to further compromise if the user then accesses sensitive internal resources.

Generated by OpenCVE AI on June 9, 2026 at 20:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Experience Manager to a version that includes the security fix, such as the latest patch or release following the advisory.
  • If an upgrade is not immediately possible, apply a content security policy or web‑application firewall rule that blocks inline script execution in form fields.
  • Review and cleanse any previously stored data that may contain malicious scripts, removing or sanitizing affected form fields.

Generated by OpenCVE AI on June 9, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
Vendors & Products Adobe experience Manager

Tue, 09 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Vendors & Products Adobe
Adobe adobe Experience Manager

Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-10T13:52:41.375Z

Reserved: 2026-05-20T15:50:31.363Z

Link: CVE-2026-47949

cve-icon Vulnrichment

Updated: 2026-06-10T13:52:33.896Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T17:17:38.743

Modified: 2026-06-10T14:58:19.913

Link: CVE-2026-47949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T23:30:05Z

Weaknesses