CVE-2026-27227: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Published Sep 8, 2026
·Updated
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
1 affected component
Adobe Adobe Experience Manager
Event History
Sep 8, 2026
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
An attacker needs low-privileged access and must be able to submit content into vulnerable form fields. Exploitation also requires a victim to browse to a page containing the injected field.
2
What is the likely impact on a victim?
Malicious JavaScript can execute in the victim's browser. The vulnerability has changed scope and is rated as affecting confidentiality and integrity at a low level, with no availability impact indicated.