CVE-2026-79905: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Published Sep 8, 2026
·Updated
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
1 affected component
Adobe Adobe Experience Manager
Event History
Sep 8, 2026
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs low-privileged access to inject malicious script into vulnerable form fields. Exploitation also requires a victim to browse to a page containing the affected field.
2
What is the potential impact on users who view a malicious page?
Malicious JavaScript can execute in the victim's browser. The vulnerability has changed scope and is rated for low confidentiality and integrity impact, with no availability impact.