CVE-2026-27261 Details
Description
Rejected reason: This CVE ID was issued in error by its CVE Numbering Authority.
A stored cross-site scripting vulnerability has been identified in Adobe Experience Manager (AEM) versions 6.5.23 and earlier. This vulnerability allows low-privileged attackers to inject malicious scripts into vulnerable form fields. When a victim views the page containing the affected field, the injected JavaScript could be executed in their browser.
Users are advised to update to Adobe Experience Manager 6.5 LTS Service Pack 2, 6.5 Service Pack 24, or AEM Cloud Service Release 2026.02. Instructions for updating can be found in the release notes for each version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Mar 16, 2026 | CVE Rejected | [email protected] |
| Mar 16, 2026 | CVE Modified | [email protected] |
| Mar 11, 2026 | Initial Analysis | [email protected] |
| Mar 11, 2026 | New CVE Received | [email protected] |