Description
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: 2026-09-16
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Application
AI Analysis

Impact

Adobe Experience Manager is affected by a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious scripts into certain form fields. When a user views a page containing the compromised field, the injected JavaScript runs in the browser with the victim’s privileges, enabling actions such as defacement, session hijacking, or data exfiltration. The vulnerability is classified as CWE‑79 and is a stored XSS with a scope modification.

Affected Systems

The affected software includes Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Adobe Experience Manager cloud service offering. No specific version sub‑range is mentioned; therefore all releases within these product lines are potentially impacted.

Risk and Exploitability

The CVSS score is 5.4, indicating a medium severity. The EPSS score is less than 1 %, suggesting that real‑world exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. A low‑privileged authenticated user can submit payloads through vulnerable form fields; the attacker does not need elevated permissions or unauthenticated access. Once inserted, the data is stored and served unfiltered to any viewer, meaning the impact can reach a broad cohort if the page is widely accessed. Because the attack surface requires user interaction, the exploitation probability remains low, but the potential damage to user trust and data confidentiality could be significant.

Generated by OpenCVE AI on September 18, 2026 at 01:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Adobe‑released security patch for Experience Manager 6.5 and the cloud service, as detailed in the Adobe security advisory.
  • Validate and escape all user‑generated content before storage; implement strict input validation for form fields that accept scripts.
  • Add a Content Security Policy that restricts script execution to trusted origins and disables inline scripts wherever possible.
  • Limit permissions for low‑privileged users so they cannot submit content that will be displayed to other users, reducing the ability to store malicious payloads.

Generated by OpenCVE AI on September 18, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Adobe experience Manager Cloud Service
Vendors & Products Adobe
Adobe adobe Experience Manager
Adobe experience Manager Cloud Service

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager Experience Manager Cloud Service
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-16T17:49:42.493Z

Reserved: 2026-09-01T16:52:27.950Z

Link: CVE-2026-84397

cve-icon Vulnrichment

Updated: 2026-09-16T17:49:30.515Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T18:17:16.973

Modified: 2026-09-16T19:08:00.110

Link: CVE-2026-84397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:26Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')