Junglewise Threat Intelligence

CVE-2026-75742: Adobe Experience Manager stored cross-site scripting in form fields

CVE-2026-75742 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a web content management platform used by enterprises to create and manage digital experiences, is vulnerable to stored cross-site scripting (XSS). A low-privileged attacker can inject malicious scripts into form fields; when other users view pages containing these fields, the scripts execute in their browsers, potentially allowing attackers to steal session credentials, perform unauthorized actions, or access sensitive customer data.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Experience Manager's form field handling. An attacker with low-level privileges can inject malicious JavaScript into vulnerable form fields; because the input is stored and rendered without proper sanitization, the scripts execute in the browsers of other users who view the affected page. The attack requires the attacker to have at least low-level access to create or modify form content. This stored variant is particularly dangerous because the payload persists and affects all subsequent visitors to the page. Patch availability has not been confirmed from the provided advisory text.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References