Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting that can be exploited by a low‑privileged attacker to inject and execute malicious JavaScript in a victim's browser
Action: Patch
AI Analysis

Impact

A stored cross‑site scripting (CWE‑79) vulnerability allows an attacker who can submit data to vulnerable form fields to embed malicious JavaScript. When a victim later views a page containing the stored data, the browser executes the attacker’s code. The ability to execute arbitrary script can lead to theft of authentication tokens, session hijacking, or malicious manipulation of web content. The CVE notes a scope change, indicating that user‑controlled input may affect higher privilege operations within the system.

Affected Systems

The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific minor or patch versions are indicated in the advisory, so any deployed instance of these product lines is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet observed. Based on the description, the likely attack vector is local: an attacker with limited privileges who can submit data to the system’s form fields. Successful exploitation requires the attacker to place malicious payloads in fields that are later rendered to other users, after which the payload is executed in those users’ browsers.

Generated by OpenCVE AI on September 9, 2026 at 12:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Experience Manager update that includes the stored XSS fix as detailed in the Adobe security advisory
  • Implement input validation and output encoding on all form fields to ensure that scripts cannot be stored or rendered
  • Restrict permissions for creating or editing form content to only trusted administrators and conduct regular reviews of user‑generated content

Generated by OpenCVE AI on September 9, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T21:23:00.771Z

Reserved: 2026-08-18T01:29:54.614Z

Link: CVE-2026-75642

cve-icon Vulnrichment

Updated: 2026-09-11T21:22:55.922Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:13.427

Modified: 2026-09-11T22:16:39.150

Link: CVE-2026-75642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:15:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')