Impact
Adobe Experience Manager contains a stored Cross‑Site Scripting vulnerability that allows an attacker with low privileges to inject malicious JavaScript into form fields that are stored and served to users. When a user views the affected page, the injected script runs in their browser, potentially enabling credential theft, session hijacking, or other malicious actions. The flaw is classified as a scope‑changing XSS, which can affect a wide range of users depending on the internal distribution of the content.
Affected Systems
AEM 6.5, AEM 6.5 LTS, and AEM as a Cloud Service are impacted. Users running these versions should verify their deployment against the Adobe security advisory for CVE‑2026‑75727.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, so the current probability of exploitation is uncertain but not ruled out. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user submitting a malicious payload through a form, which is then rendered when other users view the page. No remote code execution or privilege escalation is reported; the risk is confined to the victim’s browser environment.
OpenCVE Enrichment