Junglewise Threat Intelligence

CVE-2026-75643: Adobe Experience Manager stored cross-site scripting in form fields

CVE-2026-75643 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager is a content management platform used by enterprises to build and manage digital experiences. The vulnerability allows a low-privileged user to inject malicious scripts into form fields, which are then executed in the browsers of other users who view the affected page. This could lead to account compromise, credential theft, or other attacks against end users accessing the application.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Experience Manager that affects form field components. A low-privileged attacker can inject malicious JavaScript code into vulnerable form fields, which persists in the application's data store. When other users browse to a page containing the compromised form field, the injected script executes in their browser context with their privileges, potentially allowing session hijacking, credential capture, or malware distribution. No patch availability information is currently available from the provided advisory details.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References