Junglewise Threat Intelligence

CVE-2026-75734: Adobe Experience Manager stored XSS in form fields

CVE-2026-75734 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager contains a stored cross-site scripting vulnerability in form field handling that allows low-privileged users to inject malicious scripts. When a victim visits a page containing a compromised form field, the attacker's JavaScript code executes in their browser, potentially enabling session hijacking, credential theft, or data exfiltration. The vulnerability's scope change means it may affect multiple components or have broader impact than originally assessed.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Adobe Experience Manager's form field processing. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields, which is then persisted server-side. When any user (including higher-privileged users) visits a page containing the compromised field, the malicious script executes in their browser context. No special user interaction beyond normal site browsing is required for exploitation. The vulnerability's scope designation change suggests elevated impact potential compared to typical reflected XSS, possibly affecting authentication contexts or privileged operations.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References