Stored Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-84397

5.4MEDIUM

What is CVE-2026-84397?

Adobe Experience Manager has a vulnerability that allows low-privileged attackers to exploit stored Cross-Site Scripting (XSS). This issue enables attackers to inject harmful scripts into vulnerable form fields, leading to the execution of malicious JavaScript in the browsers of unsuspecting users. When users navigate to the page containing the compromised form, their systems may become the target of various attacks due to the unauthorized script execution.

Affected Version(s)

Adobe Experience Manager 6.5 0 <= 6.5.24

Adobe Experience Manager 6.5 LTS 0

Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.