Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DOM-based Cross-site Scripting (XSS) that allows execution of user‑supplied JavaScript in the victim’s browser
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw. The defect permits an attacker to manipulate the Document Object Model in the victim’s browser and run malicious JavaScript, potentially compromising secrets, local data, or performing phishing attacks within the user’s session. The flaw is a classic input‑validation weakness, reflected in CWE‑79, and requires that the victim visit a specially crafted web page to trigger the flaw.

Affected Systems

Affected products include Adobe Experience Manager 6.5, the 6.5 LTS release, and the Adobe Experience Manager as a Cloud Service offering. Users operating these versions or hosting instances of the product are susceptible if no remedial update has been applied.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. The EPSS value is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation mandates user interaction; an attacker must entice a user to open a crafted URL. The attack surface is the client browser, and successful exploitation can lead to the execution of arbitrary JavaScript within the context of the victim’s session. Attackers could thereby steal session tokens or perform actions on behalf of the user, but major privilege escalation is not possible at the application layer.

Generated by OpenCVE AI on September 9, 2026 at 12:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe Experience Manager patch or upgrade to a version that includes the fix for the listed 6.5, 6.5 LTS, or Cloud Service releases.
  • Apply strict input validation or sanitization to all data that is subsequently rendered into the DOM, following the remediation guidance for CWE‑79 to prevent untrusted data from becoming executable code.
  • Configure a strong content‑security‑policy header and/or deploy a web‑application firewall to block execution of unauthorized scripts from malicious URLs.

Generated by OpenCVE AI on September 9, 2026 at 12:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T15:00:57.259Z

Reserved: 2026-08-10T11:07:19.627Z

Link: CVE-2026-72626

cve-icon Vulnrichment

Updated: 2026-09-09T16:41:46.266Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:01.113

Modified: 2026-09-11T13:08:12.600

Link: CVE-2026-72626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')