CVE-2026-27224: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
Who needs access to exploit this issue?
An attacker needs low-level privileges to inject malicious scripts into vulnerable form fields. Exploitation also requires a victim to browse to a page containing the affected field.
Which deployments are affected?
Adobe Experience Manager versions 6.5.23 and earlier are affected. The provided information does not state whether vulnerable form fields are present or enabled in default configurations.
What is the likely impact on a victim?
Malicious JavaScript can execute in the victim's browser. The listed impacts include low confidentiality and integrity impact, with no availability impact.