CVE-2026-75741: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs low-privileged access to Adobe Experience Manager and must be able to submit content into a vulnerable form field.
What must happen for malicious code to execute?
A victim must browse to a page that contains the vulnerable field holding the attacker’s stored script. User interaction is required, and the script executes in the victim’s browser.
What is the likely impact if exploitation succeeds?
The issue can affect confidentiality and integrity at a low level, with scope changed. Availability impact is not indicated.