CVE-2026-27226: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and what interaction is required from a victim?
An attacker needs at least low-privileged access to inject malicious script into vulnerable form fields. A victim must browse to a page containing the attacker-controlled field for the script to execute in their browser.
Which deployments are affected?
Adobe Experience Manager versions 6.5.23 and earlier are affected.
What is the potential impact after successful exploitation?
The vulnerability can cause malicious JavaScript stored in a vulnerable form field to execute in a victim's browser. The supplied severity vector indicates low impacts to confidentiality and integrity, with no availability impact.