Impact
The vulnerability is a stored Cross‑Site Scripting (XSS) flaw in Adobe Experience Manager that allows a low‑privileged attacker to inject arbitrary JavaScript into form fields that are stored and later rendered. When a user visits a page that displays the stored input, the malicious script executes in the victim’s browser, enabling the attacker to run client‑side code. The flaw is a scope‑changing vulnerability, meaning the impact may extend beyond the originally intended context.
Affected Systems
Adobe Experience Manager installations running version 6.5.24, LTS SP1, 2026.04, or any earlier release are affected. The issue is documented in Adobe’s Security Advisory APSB26‑56. Any deployment that has not applied the provided fix or upgraded past these versions should be considered vulnerable.
Risk and Exploitability
The CVSS score of 5.4 represents moderate severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be determined. The vulnerability is not listed in CISA KEV, indicating no known widespread exploitation. Because the attacker needs only low‑privileged access to submit data and the flaw allows client‑side code execution, the potential impact on confidentiality, integrity, and availability of affected users is significant.
OpenCVE Enrichment