← Back to CVE List
CVE-2026-84397NVD
Vulnerability Summary
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
CVSS v3.1 Base Metrics — Score 5.4 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- Adobe Adobe Experience Manager as a Cloud Service <= 2026.7.0
- Adobe Adobe Experience Manager 6.5 LTS <= SP2
- Adobe Adobe Experience Manager 6.5 <= 6.5.24
- Adobe Adobe Experience Manager as a Cloud Service 2026.7.0
- Adobe Adobe Experience Manager 6.5 LTS SP2
- Adobe Adobe Experience Manager 6.5 6.5.24