CVE-2026-75736: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker needs low-privileged access and must be able to submit malicious content through vulnerable form fields. Exploitation also requires a victim to browse to a page containing the injected field.
What is the likely impact if exploitation succeeds?
Malicious JavaScript can execute in the victim's browser in the context of the affected page. The stated impact includes low confidentiality and integrity effects, and the vulnerability has changed scope.
How can I tell whether an instance may be affected?
Review whether low-privileged users can enter content into the relevant Experience Manager form fields and whether that content is later displayed to other users without safe output handling. The provided information does not identify specific affected versions or fields.