CVE-2026-84397: Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Who is most likely to be exposed to this issue?
Users who browse to an Adobe Experience Manager page containing a vulnerable form field with attacker-injected content may have malicious JavaScript executed in their browser. The attacker must have low-privileged access to inject the script.
What does an attacker need to exploit the vulnerability?
The attacker needs low-privileged access and must be able to place malicious script content into a vulnerable form field. A victim must then browse to the page that contains that field.
What is the potential impact of successful exploitation?
Successful exploitation can cause malicious JavaScript to run in the victim's browser. The reported impact includes low confidentiality and integrity effects, with no availability impact.