CVE-2026-27228: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Adobe Experience Manager versions 6.5.23 and earlier are affected.
What does an attacker need to exploit this issue?
The attacker needs low-privileged access and must be able to inject malicious script into vulnerable form fields. A victim must then browse to a page containing the vulnerable field for the script to execute.
What is the likely impact if exploitation succeeds?
Malicious JavaScript can execute in the victim's browser. The stated impact includes limited confidentiality and integrity effects, with no availability impact.