Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a stored Cross‑Site Scripting flaw that can be abused by a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. When a victim visits a page containing the stored input, the injected script is executed in the victim's browser, potentially enabling session hijacking, data theft, or defacement. Because the vulnerability modifies the scope of the application, its exploitation can affect multiple users who view the compromised content.

Affected Systems

Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are all affected. No explicit version constraints are provided beyond the product families indicated.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. With no EPSS information available and the vulnerability not listed in the CISA KEV catalog, the likelihood of exploitation appears moderate; however, the flaw allows compromised web content to run arbitrary JavaScript in the context of authenticated or guest users. The attack vector is inferred to be through the application’s form submission and rendering workflow, where user input is stored and later displayed without proper sanitization. By exploiting this, an attacker can obtain and execute code within the victim’s browser session.

Generated by OpenCVE AI on September 9, 2026 at 09:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or update to a fixed version of Adobe Experience Manager 6.5, 6.5 LTS, or Cloud Service that addresses the stored XSS vulnerability.
  • Configure input validation or sanitization on form fields to strip or encode potentially malicious JavaScript before storage, ensuring that only safe content is persisted.
  • Deploy a Content Security Policy that restricts scripts to trusted origins and disallows inline JavaScript to mitigate the impact of any future XSS attempts.

Generated by OpenCVE AI on September 9, 2026 at 09:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T21:24:58.098Z

Reserved: 2026-08-18T01:29:54.621Z

Link: CVE-2026-75729

cve-icon Vulnrichment

Updated: 2026-09-11T21:24:53.422Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:20.597

Modified: 2026-09-11T22:16:42.720

Link: CVE-2026-75729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T12:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')