Description
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Published: 2026-03-11
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross‑Site Scripting (XSS) vulnerability (CWE‑79). The flaw allows a low‑privileged attacker to inject malicious JavaScript into certain form fields, which is executed in a victim’s browser when the victim accesses a page that contains the compromised field. This can lead to unintended script execution, potentially exposing confidential data or enabling further attacks from the victim’s session.

Affected Systems

All installations of Adobe Experience Manager running version 6.5.23 or earlier are impacted, including on‑premises deployments. Based on the CPE entries that reference the aem_cloud_service variant, it is inferred that cloud deployments built on the same code base may also be vulnerable, although the vendor advisory does not explicitly state this.

Risk and Exploitability

The CVSS base score of 5.4 indicates moderate severity. The EPSS score of less than 1 % suggests that wide‑scale exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalogue. The attack requires the attacker to submit content to a vulnerable form field, a capability that can be obtained by any user with write access to that field. Therefore, while exploitation is not trivial, it is feasible for an authorized user with limited privileges to activate the vulnerability.

Generated by OpenCVE AI on March 17, 2026 at 17:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Visit Adobe’s security advisory at https://helpx.adobe.com/security/products/experience-manager/apsb26-24.html to download and apply the patch that addresses versions 6.5.23 and earlier.
  • Apply the vendor patch as soon as it becomes available for the affected installation (on‑prem or cloud).
  • Restrict write permissions on the identified vulnerable form fields to trusted users only until the fix is applied.
  • Monitor for unexpected JavaScript appearing in form data or web pages after remediation to detect any missed exploitation attempts.

Generated by OpenCVE AI on March 17, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 11 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
Vendors & Products Adobe experience Manager

Wed, 11 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Vendors & Products Adobe
Adobe adobe Experience Manager

Wed, 11 Mar 2026 01:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-03-11T13:38:41.074Z

Reserved: 2026-02-18T22:02:41.381Z

Link: CVE-2026-27233

cve-icon Vulnrichment

Updated: 2026-03-11T13:30:17.247Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-11T01:16:52.977

Modified: 2026-03-11T14:57:59.740

Link: CVE-2026-27233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T14:38:38Z

Weaknesses