CVE-2026-71440: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs low-privileged access to Adobe Experience Manager and must be able to submit content to a vulnerable form field. Exploitation also requires a victim to browse to the page where the injected content is displayed.
What is the likely impact if exploitation succeeds?
Malicious JavaScript can execute in the victim's browser, with low confidentiality and integrity impact indicated. The vulnerability has changed scope, meaning the effects can extend beyond the security authority of the vulnerable component.
Are users exposed simply by visiting a vulnerable page?
Yes. Once malicious script has been stored in a vulnerable field, a victim may trigger execution by browsing to the page containing that field.