CVE-2026-27258: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27258?
CVE-2026-27258 is classified as a high-severity vulnerability due to its potential to cause application denial-of-service.
How do I fix CVE-2026-27258?
To mitigate CVE-2026-27258, update to a version of the Adobe DNG SDK that is 1.7.1 2502 or later.
What causes the vulnerability in CVE-2026-27258?
CVE-2026-27258 is caused by an out-of-bounds write that can lead to memory corruption.
What are the potential impacts of CVE-2026-27258?
The potential impacts of CVE-2026-27258 include application crashes and denial-of-service due to corrupted memory.
Who is affected by CVE-2026-27258?
CVE-2026-27258 affects users of Adobe DNG SDK versions 1.7.1 2502 and earlier.