Stored Cross-Site Scripting in Adobe Experience Manager
CVE-2026-75734

5.4MEDIUM

What is CVE-2026-75734?

Adobe Experience Manager has a vulnerability that allows low-privileged attackers to perform stored Cross-Site Scripting (XSS) attacks. This occurs when an attacker injects malicious scripts into vulnerable form fields. As a result, these scripts can be executed in the browser of any user who visits the affected page, leading to potential data exposure and unauthorized actions. It's crucial for administrators to apply recommended security measures to safeguard against this threat.

Affected Version(s)

Adobe Experience Manager 6.5 0 <= 6.5.24

Adobe Experience Manager 6.5 LTS 0

Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.