
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27264 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) affecting versions 6.5.23 and earlier, as well as AEM Cloud Service versions prior to 2026.2.0. It was published on March 11, 2026, and is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). Note that this CVE has been marked as Rejected by its CVE Numbering Authority, indicating it was issued in error; however, the underlying vulnerability description and patch details remain associated with Adobe's security advisory APSB26-24. The CVSS v3.1 base score is 5.4 (Medium) (Adobe Advisory).
The vulnerability is rooted in insufficient input sanitization (CWE-79) within form fields of Adobe Experience Manager, allowing stored XSS payloads to persist in the application. A low-privileged, authenticated attacker can inject malicious JavaScript into vulnerable form fields; the script is then stored server-side and executes in the browsers of other users who visit the affected page. The attack vector is network-based, requires low privileges and user interaction (a victim browsing to the compromised page), and results in a changed scope — meaning the impact extends beyond the vulnerable component itself (Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in victims' browsers, enabling session token theft, credential harvesting, and account compromise. Because the scope is changed, the impact can extend beyond the AEM application itself to affect users' browsers and any data accessible within their sessions. Confidentiality and integrity are both partially impacted, while availability is unaffected (Adobe Advisory).
Adobe has addressed this vulnerability in AEM version 6.5.24.0 and later; users of AEM Cloud Service should upgrade to version 2026.2.0 or later. As supplementary mitigations, administrators should implement a Content Security Policy (CSP) to restrict script execution, review and sanitize existing form field content for injected scripts, and monitor user accounts for signs of session hijacking or unauthorized activity (Adobe Advisory).
The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Adobe products that could allow for arbitrary code execution, referencing the broader APSB26-24 patch bundle. Tenable flagged the issue in its plugin pipeline, and several vulnerability aggregators (VulDB, CVEFeed, INCIBE) published entries shortly after disclosure. Community attention has been limited, consistent with the medium severity rating and the CVE's subsequent rejection status.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."