Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting
Action: Apply Patch
AI Analysis

Impact

A stored cross‑site scripting vulnerability exists in Adobe Experience Manager that allows a low‑privileged attacker to inject malicious JavaScript into vulnerable form fields. When a victim visits the page containing the injected script, the code executes in the victim’s browser, potentially stealing cookies, hijacking sessions, or redirecting the user to malicious sites. Scope changes indicate the attack could affect the entire web application rather than just a single form.

Affected Systems

Adobe Experience Manager 6.5, the 6.5 LTS release, and the Experience Manager as a Cloud Service are impacted. Any instance running these versions without the vendor‑supplied fix is vulnerable.

Risk and Exploitability

The CVSS score of 5.4 classifies this issue as moderate severity, and the EPSS score is not available, so the likelihood of exploitation is uncertain but cannot be ruled out. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. However, given that a low‑privileged attacker can submit data that is stored and later rendered, an attacker could leverage the XSS to compromise end users within the same organization or its customers, posing a risk especially in environments where form data is publicly visible.

Generated by OpenCVE AI on September 9, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Adobe Experience Manager update or patch provided in the APSb26‑98 bulletin.
  • Ensure all form field output is properly encoded or sanitized to prevent injection of script content.
  • Implement a Content Security Policy that restricts execution of inline scripts and reduces the impact of any residual XSS content.

Generated by OpenCVE AI on September 9, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T15:44:34.563Z

Reserved: 2026-08-18T01:29:54.622Z

Link: CVE-2026-75741

cve-icon Vulnrichment

Updated: 2026-09-09T15:44:31.471Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:21.897

Modified: 2026-09-10T13:53:01.523

Link: CVE-2026-75741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')