Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-07-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject and execute malicious JavaScript within a victim’s browser. The flaw requires the victim to visit a crafted webpage, after which the attacker can influence the DOM environment. The impact includes potential data theft, session hijacking, or defacement, as the script runs under the user’s privileges. The CVE notes that the scope is changed, indicating that the vulnerability might affect resources beyond the immediate user context.

Affected Systems

Adobe Experience Manager versions 6.5 and 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. The vulnerability applies to all deployments of these products regardless of environment.

Risk and Exploitability

The CVSS score of 5.4 rates the issue as moderate severity, and the EPSS score of less than 1 % implies a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited current exploitation activity. Exfiltration of data or defacement could result, but since the flaw requires user interaction with a crafted page, it is not remotely exploitable without an initial social engineering step. The noted scope change signals that a successful exploit could potentially cross privilege boundaries, but the overall risk remains moderate.

Generated by OpenCVE AI on July 31, 2026 at 05:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Experience Manager updates that fix the DOM‑based XSS flaw
  • Configure a web application firewall to detect and block malicious script payloads
  • Ensure all user‑supplied input is sanitized and validated to prevent unintended DOM manipulation

Generated by OpenCVE AI on July 31, 2026 at 05:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T19:38:48.918Z

Reserved: 2026-05-21T15:28:38.130Z

Link: CVE-2026-48255

cve-icon Vulnrichment

Updated: 2026-07-15T17:40:25.993Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')