Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting enabling arbitrary JavaScript execution in end‑user browsers.
Action: Patch
AI Analysis

Impact

Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability. A low‑privileged attacker can inject malicious JavaScript into vulnerable form fields. When a victim opens the page containing the stored payload, the script runs in their browser. The flaw is a classic input validation issue (CWE‑79) that changes the scope of the affected content and data.

Affected Systems

The vulnerability applies to Adobe Experience Manager 6.5 and its LTS version, as well as the Cloud Service edition. No specific build numbers are provided, so every deployment of these products is potentially impacted until a patch is installed.

Risk and Exploitability

The vulnerability scores a CVSS of 5.4, indicating moderate severity. The EPSS score is not available and the flaw has not been reported in the KEV list. Attacks would require the attacker to be able to submit data to a vulnerable form; the stored payload is then displayed to any user who visits the affected page, which can lead to session hijacking or credential theft. The likelihood of exploitation in the wild is uncertain, but the impact on confidentiality, integrity, and availability is limited to the victim’s browser environment.

Generated by OpenCVE AI on September 9, 2026 at 11:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Experience Manager security update that addresses the stored XSS flaw.
  • Configure form input handling so that all user‑supplied content is properly sanitized and output‑encoded before rendering to prevent script injection.
  • If a patch is not immediately available, restrict or disable access to the affected form fields until the fix is applied and verify that the configuration change blocks script execution.

Generated by OpenCVE AI on September 9, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T13:23:20.762Z

Reserved: 2026-08-18T01:29:54.622Z

Link: CVE-2026-75734

cve-icon Vulnrichment

Updated: 2026-09-09T13:23:17.567Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:21.083

Modified: 2026-09-10T13:52:44.583

Link: CVE-2026-75734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:00:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')