Description
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-06-09
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier contain a stored XSS flaw (CWE-79). A low‑privileged attacker can add malicious JavaScript into form fields that the system stores and later shows to other users. When a victim visits the page containing the field, the browser executes the attacker’s script, enabling the attacker to hijack the user’s session, steal credentials, or perform other client‑side attacks. The flaw resides in the way the product handles user‑submitted form data, and its CVSS score of 5.4 reflects a moderate severity level.

Affected Systems

The affected products are Adobe Experience Manager releases 6.5.24, the LTS SP1 variant, and the 2026.04 release, as well as any earlier builds. Users who run these versions and allow form input to be stored in a user‑modifiable area are at risk. The vulnerability is tied to generic form fields, which could appear in data entry, content management, and workflow components.

Risk and Exploitability

The risk is moderate, and the vulnerability can be exploited by anyone who can submit data through a vulnerable form, without needing privileged access. The lack of an EPSS score makes exact exploitation likelihood unclear, but the CVSS rating of 5.4 indicates it could have a noticeable impact if abused. Because the flaw is stored, it can persist across sessions, and its presence in the KEV catalog is not yet recorded. Attackers typically would inject JavaScript via the form, which is then rendered to other users’ browsers, granting a range of client‑side attacks. Preventing execution of untrusted input or applying the vendor patch are the primary defenses.

Generated by OpenCVE AI on June 9, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Experience Manager to a patched release newer than 6.5.24, LTS SP1, or 2026.04 to eliminate the flaw.
  • If an immediate upgrade is not feasible, limit permissions so that only trusted administrators can submit or edit form content, and implement server‑side sanitization or a content security policy to neutralize script tags.
  • Perform security testing to confirm that malicious scripts can no longer be persisted in form fields and that any remaining XSS vectors are sealed.

Generated by OpenCVE AI on June 9, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Vendors & Products Adobe
Adobe adobe Experience Manager

Tue, 09 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-09T17:40:49.418Z

Reserved: 2026-05-20T15:50:31.363Z

Link: CVE-2026-47954

cve-icon Vulnrichment

Updated: 2026-06-09T17:40:41.734Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-06-09T17:17:39.240

Modified: 2026-06-09T19:30:24.713

Link: CVE-2026-47954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T01:45:18Z

Weaknesses