CVE-2026-47970: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Adobe Experience Manager (unneeded form components)from your environment.Disable or uninstall any unnecessary AEM form components or plugins that accept user-supplied HTML/inputs until a vendor-supplied fix is available.
- Configuration
Enable and enforce server-side input validation and proper output encoding/escaping for all form fields in Adobe Experience Manager (AEM) to prevent stored XSS (affects AEM versions 6.5.24, LTS SP1, 2026.04 and earlier).
Adobe Experience Manager (forms) server-side input validation and output encoding = enabled - Compensating control
Deploy a Web Application Firewall (WAF) or application-layer filters to detect and block XSS payloads targeting AEM form fields, and where feasible restrict access to form submission endpoints to authenticated users or trusted IP ranges.
- Operational
Audit existing stored form content in AEM for embedded JavaScript and other malicious payloads; remove or sanitize any offending entries and monitor logs for suspicious form submissions.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47970?
CVE-2026-47970 has a medium severity score of 5.4.
How do I fix CVE-2026-47970?
To fix CVE-2026-47970, upgrade to Adobe Experience Manager version 6.5.25 or later.
What type of vulnerability is CVE-2026-47970?
CVE-2026-47970 is a stored Cross-Site Scripting (XSS) vulnerability.
Who can exploit CVE-2026-47970?
CVE-2026-47970 can be exploited by a low-privileged attacker.
What impact does CVE-2026-47970 have on users?
CVE-2026-47970 can allow malicious scripts to be executed in a victim's browser.