Description
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-06-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Experience Manager versions up to and including 6.5.24, LTS SP1, and the 2026.04 release contain a DOM‑based Cross‑Site Scripting flaw (CWE‑79). An attacker who can lure a victim to a specially crafted URL can insert malicious JavaScript that runs in the victim’s browser. Because the script executes under the user’s privileges, it may read sensitive data on the page or perform actions on the user’s behalf. The vulnerability requires user interaction and does not alter system state, but it enables session hijacking or data theft if the attacker can inject scripts that read cookies or local storage.

Affected Systems

Adobe Experience Manager deployments running version 6.5.24, LTS SP1, 2026.04, or earlier are affected. Organizations using any of these releases should examine whether their instances are currently deployed and whether any custom code might be exposed via URLs that can be manipulated.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The flaw is a conventional DOM‑based XSS that requires a victim to click a malicious link; thus, it is an attack that relies on social engineering or phishing. An attacker could exploit it on any device a user accesses, including mobile browsers. Because the script runs in the victim’s context, it can exfiltrate data or inject further payloads. The lack of an exploit community score suggests no widespread automated payloads exist, but the vulnerability could still be leveraged manually by an attacker.

Generated by OpenCVE AI on June 9, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe's official security update for AEM 6.5.24, LTS SP1, 2026.04 and later.
  • Update all AEM instances to the latest supported release to remove the vulnerable code path.
  • Add input validation and sanitization for any URL parameters that populate the DOM, following CWE‑79 mitigation guidelines.

Generated by OpenCVE AI on June 9, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
Vendors & Products Adobe experience Manager

Tue, 09 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Experience Manager
Vendors & Products Adobe
Adobe adobe Experience Manager

Tue, 09 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Adobe Experience Manager Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-09T18:38:52.603Z

Reserved: 2026-05-20T15:50:31.363Z

Link: CVE-2026-47946

cve-icon Vulnrichment

Updated: 2026-06-09T18:35:54.363Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T17:17:38.307

Modified: 2026-06-10T15:03:55.353

Link: CVE-2026-47946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T23:30:05Z

Weaknesses