Junglewise Threat Intelligence

CVE-2026-75740: Adobe Experience Manager stored XSS in form fields

CVE-2026-75740 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management system used by enterprises to build and manage digital experiences, contains a stored cross-site scripting (XSS) vulnerability in form fields. A low-privileged attacker can inject malicious scripts that execute in the browsers of other users who view affected pages, potentially leading to session hijacking, credential theft, or malware distribution.

Technical details

This is a stored XSS vulnerability in Adobe Experience Manager's form field handling. An attacker with low privileges can inject malicious JavaScript into vulnerable form fields; the injected script is stored server-side and executes in the browsers of any user who views the affected page. The scope is noted as "changed," indicating the vulnerability may affect components beyond the form field itself. No patch status is specified in the advisory. The attack requires the attacker to have at least low-level access to submit or modify form content.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References