CVE-2026-27253: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs low-privileged access sufficient to submit content into a vulnerable form field. Exploitation also requires a victim to browse a page containing the injected field.
Which deployments are affected?
Adobe Experience Manager 6.5.23 and earlier are affected. The available information does not state whether vulnerable form fields are present or reachable in a default configuration.
What is the likely impact on a victim?
Injected JavaScript can execute in the victim's browser. The vulnerability is rated with low confidentiality and integrity impact and no availability impact.