---
id: CVE-2026-27222
title: >-
  Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS)
  vulnerability that could be abused by a low-privileged attacker to inject
  malicious scripts into vulnerable form fields
summary: >-
  Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS)
  vulnerability that could be abused by a low-privileged attacker to inject
  malicious scripts into vulnerable form fields. Malicious JavaScript may be
  executed in …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: adobe
product: bridge
affected:
  - bridge < 15.1.5
  - 'bridge >= 16.0, < 16.0.3'
patched:
  - bridge 16.0.3
published: '2026-04-14'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:17:31.397'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27222'
references:
  - url: >-
      https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-04-15T17:38:19.845585Z'
epss: 0.00629
epssPercentile: 0.47934
ingestedAt: '2026-09-08T20:10:03.219Z'
---

## Overview

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

## Affected

- `bridge < 15.1.5`
- `bridge >= 16.0, < 16.0.3`

## Remediation

Upgrade past the affected range:

- `bridge 16.0.3`
