Impact
A stored cross‑site scripting vulnerability exists in Adobe Experience Manager, allowing a low‑privileged attacker to inject malicious JavaScript into form fields. When a victim visits a page containing an affected field, the injected script runs in their browser, potentially enabling session hijacking, data theft, or further malicious activity. The flaw surfaces as a change in scope, meaning the attacker’s inputs are reflected back to the user without proper sanitization.
Affected Systems
Vulnerable Adobe Experience Manager releases include 6.5.24, the LTS SP1 build, and the 2026.04 release, as well as any earlier versions of the product. The vulnerability applies to all installations where these versions are deployed.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, suggesting no recent exploitation data is reported. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the exploitation of web forms that accept user input and subsequently display that input without adequate encoding. A low‑privileged user can inject script data, which is persisted and later executed in the victim’s browser.
OpenCVE Enrichment