Junglewise Threat Intelligence

CVE-2026-75730: Adobe Experience Manager stored XSS in form fields

CVE-2026-75730 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used platform for managing digital content and customer experiences, contains a stored cross-site scripting vulnerability in form handling components. A low-privileged user can inject malicious scripts that execute in the browsers of other users viewing affected pages, potentially leading to session hijacking, credential theft, or unauthorized administrative actions.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager's form field handling. The vulnerability stems from insufficient input validation and output encoding of user-supplied data in form fields; an attacker with low privileges can persist malicious JavaScript in the application, which then executes in the context of victim browsers when they access pages containing the vulnerable field. The scope is changed, indicating the vulnerability may affect other components or users beyond the attacker's privilege level. Network access and low-privileged account credentials are required for exploitation; no special user interaction beyond browsing the affected page is needed. Patches are available via Adobe's APSB26-98 security bulletin.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References