Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored client‑side code execution via Cross‑Site Scripting
Action: Apply patch
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a stored Cross‑Site Scripting flaw that allows a low‑privileged attacker to inject and persist malicious JavaScript in form fields. When another user views the affected page, the script runs in that victim’s browser, enabling credential theft, phishing, or other client‑side attacks. The vulnerability changes scope, indicating that the impact is confined to the user interacting with the malicious page rather than affecting the server itself.

Affected Systems

Adobe Experience Manager versions 6.5, 6.5 LTS, and the Adobe Experience Manager As a Cloud Service are all affected by this flaw. Any deployment of these products that stores data from user input in form fields is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.4 classifies the vulnerability as moderate in severity. No EPSS data are available, and the issue is not listed in CISA’s Known Exploited Vulnerabilities catalog, suggesting limited field instruction. The attack requires an attacker to have access to edit a form field, but does not allow direct server‑side code execution. Exploitation is thus client‑side and requires a victim to load a page containing the malicious input.

Generated by OpenCVE AI on September 9, 2026 at 13:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Experience Manager to the latest version that includes the vendor‑issued fix for the XSS vulnerability.
  • Add thorough input validation for all form fields and encode output before rendering to mitigate script injection.
  • Deploy a Content Security Policy that restricts script execution to trusted sources, reducing the impact of any residual injection.

Generated by OpenCVE AI on September 9, 2026 at 13:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T21:00:28.938Z

Reserved: 2026-08-25T14:55:07.586Z

Link: CVE-2026-79905

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:39.027

Modified: 2026-09-10T21:17:47.163

Link: CVE-2026-79905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:15:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')