Junglewise Threat Intelligence

CVE-2026-75729: Adobe Experience Manager stored XSS in form fields

CVE-2026-75729 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used web content management and digital experience platform, is vulnerable to stored cross-site scripting (XSS) attacks in form fields. A low-privileged attacker can inject malicious JavaScript code that persists in the system and executes in victims' browsers, potentially enabling account theft, credential harvesting, or redirection to malicious sites.

Technical details

The vulnerability is a stored XSS flaw in Adobe Experience Manager's form field handling that fails to properly sanitize or encode user-supplied input. An attacker with low-level privileges can inject malicious JavaScript payloads into vulnerable form fields, which are stored server-side and executed in the browsers of any user who views the affected page. The scope is marked as "changed," suggesting potential impact beyond the immediate vulnerable component. No authentication bypass is required—only low-level user access is needed to inject the payload. Patches are expected to be available from Adobe.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References