Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS in Adobe Experience Manager
Action: Immediate Patch
AI Analysis

Impact

Adobe Experience Manager has a stored cross‑site scripting vulnerability that allows a low‑privileged attacker to inject malicious JavaScript into form fields. When the victim visits the affected page, the browser executes the injected script, which can lead to session hijacking, data theft, or other malicious activity. The weakness is identified as CWE‑79 and the scope is changed, indicating that the exploited flaw can affect the overall system beyond the initial input.

Affected Systems

All instances of Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are potentially impacted. Specific affected versions are not enumerated in the advisory, so any build of these products may contain the flaw until an update is applied.

Risk and Exploitability

The CVSS score of 5.4 places this vulnerability in the medium‑to‑high range. Although EPSS data is not available, the stored nature of the flaw and the requirement for only low‑privileged access mean it is likely to be exploitable by attackers who can submit content. The vulnerability is not listed in CISA’s KEV catalog, but it still poses a notable risk to organizations using the affected products. Attackers generally must have web access to submit malicious form data and rely on unsuspecting users visiting the resulting pages.

Generated by OpenCVE AI on September 9, 2026 at 09:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Adobe Experience Manager security update released in the APS-26-98 advisory
  • Enable a strict content security policy that blocks execution of inline scripts on all pages
  • Configure server‑side input sanitization and output encoding for all user‑generated content

Generated by OpenCVE AI on September 9, 2026 at 09:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T21:00:28.189Z

Reserved: 2025-11-11T22:48:38.835Z

Link: CVE-2025-64854

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:17:26.923

Modified: 2026-09-11T14:11:28.337

Link: CVE-2025-64854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')