Junglewise Threat Intelligence

CVE-2026-71440: Adobe Experience Manager stored cross-site scripting in form fields

CVE-2026-71440 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used digital content management platform, contains a stored cross-site scripting vulnerability in its form field handling. An attacker with low-level user access can inject malicious scripts that execute in other users' browsers when they view the affected page, potentially leading to account compromise or data theft.

Technical details

This is a stored (persistent) cross-site scripting vulnerability in Adobe Experience Manager's form field components. The vulnerability allows a low-privileged authenticated user to inject malicious JavaScript into form fields; the injected payload is stored server-side and executed in victims' browsers when they access the affected page. The scope classification indicates this crosses privilege or security boundary. No evidence of exploitation in the wild has been reported. A patch is expected from Adobe's APSB26-98 security bulletin.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References