CVE-2026-75738: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs low-privileged access to Adobe Experience Manager and must be able to submit content through a vulnerable form field. Exploitation also requires a victim to browse to a page containing the injected field.
What is the likely impact if exploitation succeeds?
Malicious JavaScript can execute in the victim's browser. The supplied vector indicates scope can change and that confidentiality and integrity impact are low, while availability impact is not indicated.
How can an organization determine whether it may be affected?
Review Adobe Experience Manager form fields that accept content from low-privileged users and identify pages where that content is later rendered to other users. Check the Adobe security advisory referenced in the CVE record for affected-product and remediation details.