Junglewise Threat Intelligence

CVE-2026-75737: Adobe Experience Manager stored Cross-Site Scripting in form fields

CVE-2026-75737 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used digital experience platform, contains a stored cross-site scripting (XSS) vulnerability that allows low-privileged users to inject malicious scripts into form fields. When other users view pages containing these compromised fields, the injected scripts execute in their browsers, potentially compromising their accounts, stealing sensitive data, or performing unauthorized actions on their behalf. This vulnerability bypasses normal security boundaries because the malicious content persists in the system rather than being lost after a single interaction.

Technical details

The vulnerability is a stored cross-site scripting flaw in Adobe Experience Manager's form field handling. A low-privileged attacker can inject arbitrary JavaScript into specific form fields without proper input sanitization or output encoding. The malicious payload is stored in the application's database and executed in the browser of any user who accesses the affected page or component. The vulnerability changes the security scope of the application, suggesting a boundary breach between privilege levels. This represents a high-impact client-side vulnerability since no additional authentication or special conditions are required for the victim to trigger the exploit—only viewing the affected page is necessary.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References