CVE-2026-75730: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Published Sep 8, 2026
·Updated
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
1 affected component
Adobe Adobe Experience Manager
Event History
Sep 8, 2026
CVE Published
via MITRE·07:57 PM
Data Sourced
via MITRE·07:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue, and what interaction is required?
A low-privileged attacker can inject malicious scripts into vulnerable form fields. A victim must browse to a page containing the affected field for the JavaScript to execute in their browser.
2
What is the likely impact if exploitation succeeds?
The vulnerability can result in execution of malicious JavaScript in a victim's browser. The stated impact includes limited confidentiality and integrity effects, and the scope is changed.