CVE-2026-27254: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a low-privileged Adobe Experience Manager account and must be able to submit malicious script content through a vulnerable form field. Exploitation also requires a victim to browse to a page that contains the stored malicious content.
What is the potential impact on users who view an affected page?
Malicious JavaScript can execute in the victim's browser in the context of the affected page. The stated impact includes low confidentiality and integrity impact, with no availability impact.
Which Adobe Experience Manager versions are affected?
Adobe Experience Manager 6.5.23 and earlier are affected.