Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting executed in the victim’s browser context
Action: Apply patch
AI Analysis

Impact

Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting flaw that allows an attacker to manipulate the browser’s Document Object Model to inject and execute malicious JavaScript. The vulnerability requires a victim to visit a crafted web page, after which arbitrary script can run with the same privileges as the victim’s session, potentially leading to credential theft, session hijacking, or defacement. The description indicates a change of scope, signifying that the attacker might gain additional privileges within the application context, but the flaw remains client‑side and does not provide remote code execution on the server.

Affected Systems

Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are the affected products covered by the advisory.

Risk and Exploitability

The CVSS score of 5.4 classifies the severity as medium; no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The primary attack vector requires user interaction through a crafted webpage, meaning that unsolicited attacks are less probable. Nonetheless, the potential for the attacker to inject malicious code into a victim’s browser and the possible scope elevation warrant immediate attention.

Generated by OpenCVE AI on September 9, 2026 at 12:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe Experience Manager security updates for version 6.5 and 6.5 LTS as soon as they are available to address the DOM-based XSS vulnerability.
  • Configure a strict Content Security Policy that disallows inline scripts and restricts script sources to trusted domains, reducing the impact of any remaining client‑side weaknesses.
  • Instruct users and administrators to be cautious when accessing unfamiliar URLs; consider using a web filter that blocks suspicious content associated with XSS attacks.

Generated by OpenCVE AI on September 9, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T14:59:44.242Z

Reserved: 2026-08-10T15:34:11.880Z

Link: CVE-2026-19479

cve-icon Vulnrichment

Updated: 2026-09-09T16:41:29.191Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:17:29.213

Modified: 2026-09-11T14:08:44.817

Link: CVE-2026-19479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:15:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')