CVE-2026-27262: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27262?
CVE-2026-27262 is classified as a high severity vulnerability due to its potential to allow stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-27262?
To fix CVE-2026-27262, upgrade Adobe Experience Manager to version 6.5.24 or later.
What types of software are affected by CVE-2026-27262?
Affected software includes Adobe Experience Manager versions 6.5.23 and earlier.
What vulnerabilities can result from CVE-2026-27262?
CVE-2026-27262 can lead to the injection of malicious scripts into vulnerable form fields, potentially compromising user data.
Is there a workaround for CVE-2026-27262 if I cannot update immediately?
There are no specific workarounds documented for CVE-2026-27262, so upgrading is the recommended course of action.