
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27261 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) affecting versions 6.5.23 and earlier, as well as AEM Cloud Service versions prior to 2026.02.0. A low-privileged attacker can inject malicious scripts into vulnerable form fields, which are then executed in a victim's browser when they visit the affected page. The CVE was initially published on March 11, 2026, and has since been marked as Rejected by its CVE Numbering Authority, indicating it was issued in error; however, the underlying vulnerability details were documented under Adobe's security advisory APSB26-24. The CVSS v3.1 base score is 5.4 (Medium) (Adobe Advisory, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored (persistent) variant. A low-privileged authenticated attacker can submit malicious JavaScript payloads into AEM form fields that are not properly sanitized or encoded before being stored and subsequently rendered to other users. Exploitation requires user interaction — a victim must browse to the page containing the compromised field — and the injected script executes within the victim's browser session in the context of the AEM application. No public proof-of-concept exploit code has been identified (Adobe Advisory, Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who view pages containing the injected content, potentially enabling session token theft, credential harvesting, unauthorized actions performed on behalf of victims, and integrity compromise of displayed content. Because AEM is commonly used as an enterprise content management platform, a compromised AEM instance could expose sensitive organizational data or facilitate further attacks against authenticated users, including administrators. Availability is not directly impacted by this vulnerability (Feedly, Adobe Advisory).
Adobe has released patches addressing this vulnerability. Users should upgrade Adobe Experience Manager to version 6.5.24 or later for standard on-premises installations, or to version 2026.02.0 or later for AEM Cloud Service deployments. As additional hardening measures, organizations should implement Content Security Policy (CSP) headers to restrict unauthorized script execution, deploy a web application firewall (WAF) to filter malicious input, monitor form submissions for suspicious script patterns, and restrict form field modification privileges to only necessary personnel (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products that could allow for arbitrary code execution, referencing the March 2026 Adobe patch cycle that includes this issue (CIS Advisory). Community coverage was limited to automated vulnerability tracking platforms such as VulDB, CVEFeed, and INCIBE-CERT, with no notable independent researcher commentary or significant social media discussion identified. The formal rejection of the CVE ID by Adobe's CNA has not generated significant public controversy.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."