CVE-2026-27251: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Experience Managerto a version that resolves this vulnerability.Fixed in 6.5.23
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2026-27251?
CVE-2026-27251 allows low-privileged attackers to inject malicious scripts into vulnerable form fields, leading to stored cross-site scripting (XSS) attacks.
Which versions of Adobe Experience Manager are affected by CVE-2026-27251?
Adobe Experience Manager versions 6.5.23 and earlier are affected by CVE-2026-27251.
How can I mitigate the risks associated with CVE-2026-27251?
To mitigate CVE-2026-27251, upgrade to Adobe Experience Manager version 6.5.24 or later.
Who could potentially exploit CVE-2026-27251?
CVE-2026-27251 can be exploited by low-privileged attackers who can access the vulnerable form fields.
What is the nature of the vulnerability described in CVE-2026-27251?
CVE-2026-27251 is a stored cross-site scripting (XSS) vulnerability classified under CWE-79.