Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability that could be abused by a low‑privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed when a victim visits the page containing the field. The vulnerability changes the security scope, allowing an attacker to persistently impact the user session or content integrity.

Affected Systems

Affected products include Adobe Experience Manager 6.5, 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific version constraints are listed, so all current releases of these offerings are potentially susceptible.

Risk and Exploitability

The CVSS score of 5.4 denotes a moderate impact; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker with low privileges could exploit the flaw through editable content or form fields, potentially injecting script that runs in the victim’s browser. Because the attacker only needs content editing rights, the risk of exploitation is considered moderate but should be mitigated promptly.

Generated by OpenCVE AI on September 9, 2026 at 09:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Adobe Experience Manager security advisory for the latest patch and install it.
  • Restrict write/edit permissions on form fields to trusted users or roles to reduce the attack surface.
  • Implement a Content Security Policy that disallows inline JavaScript to limit the impact of any remaining injection attempts.

Generated by OpenCVE AI on September 9, 2026 at 09:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T21:25:39.612Z

Reserved: 2026-08-18T01:29:54.622Z

Link: CVE-2026-75735

cve-icon Vulnrichment

Updated: 2026-09-11T21:25:34.699Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:21.200

Modified: 2026-09-11T22:16:43.220

Link: CVE-2026-75735

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')