CVE-2026-27264
Adobe Experience Manager vulnerability analysis and mitigation

Overview

CVE-2026-27264 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) affecting versions 6.5.23 and earlier, as well as AEM Cloud Service versions prior to 2026.2.0. It was published on March 11, 2026, and is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). Note that this CVE has been marked as Rejected by its CVE Numbering Authority, indicating it was issued in error; however, the underlying vulnerability description and patch details remain associated with Adobe's security advisory APSB26-24. The CVSS v3.1 base score is 5.4 (Medium) (Adobe Advisory).

Technical details

The vulnerability is rooted in insufficient input sanitization (CWE-79) within form fields of Adobe Experience Manager, allowing stored XSS payloads to persist in the application. A low-privileged, authenticated attacker can inject malicious JavaScript into vulnerable form fields; the script is then stored server-side and executes in the browsers of other users who visit the affected page. The attack vector is network-based, requires low privileges and user interaction (a victim browsing to the compromised page), and results in a changed scope — meaning the impact extends beyond the vulnerable component itself (Adobe Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in victims' browsers, enabling session token theft, credential harvesting, and account compromise. Because the scope is changed, the impact can extend beyond the AEM application itself to affect users' browsers and any data accessible within their sessions. Confidentiality and integrity are both partially impacted, while availability is unaffected (Adobe Advisory).

Mitigation and workarounds

Adobe has addressed this vulnerability in AEM version 6.5.24.0 and later; users of AEM Cloud Service should upgrade to version 2026.2.0 or later. As supplementary mitigations, administrators should implement a Content Security Policy (CSP) to restrict script execution, review and sanitize existing form field content for injected scripts, and monitor user accounts for signs of session hijacking or unauthorized activity (Adobe Advisory).

Community reactions

The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Adobe products that could allow for arbitrary code execution, referencing the broader APSB26-24 patch bundle. Tenable flagged the issue in its plugin pipeline, and several vulnerability aggregators (VulDB, CVEFeed, INCIBE) published entries shortly after disclosure. Community attention has been limited, consistent with the medium severity rating and the CVE's subsequent rejection status.

Additional resources


SourceThis report was generated using AI

Related Adobe Experience Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48359CRITICAL9.6
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026
CVE-2026-48310HIGH8.6
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026
CVE-2026-48355MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026
CVE-2026-48263MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026
CVE-2026-48262MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management