Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross-site scripting (XSS)
Action: Patch Now
AI Analysis

Impact

Adobe Experience Manager is affected by a stored cross‑site scripting vulnerability that allows a low‑privileged attacker to inject malicious scripts into form fields. If the victim visits a page that renders the compromised field, the injected JavaScript executes in the victim’s browser. The flaw is a stored XSS weakness (CWE‑79) that can be abused to compromise user confidentiality and potentially deliver further attack payloads. The vulnerability includes a scope change, indicating that the impact may extend beyond the originator of the request.

Affected Systems

Affected products include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. Specific version details are not provided beyond the product families; the information indicates that any deployment of these product lines is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.4 classifies the vulnerability as moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation can be achieved remotely through the web interface using low‑privilege credentials, and the attacker can target any user who subsequently accesses the vulnerable page. Given the absence of a low exploitation probability score, the risk is primarily driven by the moderate severity and the ease of exploitation via ordinary web traffic.

Generated by OpenCVE AI on September 9, 2026 at 12:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Experience Manager update that addresses the stored XSS issue (see the Adobe security advisory for patch details).
  • Review all form field configurations in the AEM instance and enforce strict input validation and output encoding to prevent accidental storage of executable scripts.
  • Enable or configure Adobe Experience Manager’s built‑in XSS protection mechanisms, such as safe‑html policies, and monitor system logs for anomalous script execution attempts.

Generated by OpenCVE AI on September 9, 2026 at 12:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T16:00:39.570Z

Reserved: 2026-02-18T22:02:41.381Z

Link: CVE-2026-27227

cve-icon Vulnrichment

Updated: 2026-09-09T16:00:36.079Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:17:31.893

Modified: 2026-09-11T12:48:48.250

Link: CVE-2026-27227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T15:15:21Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')