Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side execution of malicious JavaScript via DOM‑based Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to manipulate the environment of a victim’s browser and execute arbitrary client‑side JavaScript. The flaw requires the victim to load a specially crafted web page and the vulnerability’s scope is changed, indicating that the impact can extend beyond the original request origin.

Affected Systems

The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific modified product versions were disclosed in the public advisory, so any deployment of the listed products could be at risk.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. Because the exploit requires victim interaction to visit a malicious page, the probability of exploitation is not quantified due to lack of an EPSS score, and the vulnerability is not listed in CISA’s KEV catalog. The risk to an organization depends on the presence or absence of mitigations such as input sanitisation or client‑side controls.

Generated by OpenCVE AI on September 9, 2026 at 13:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Adobe’s advisory and apply any published fix or upgrade for Adobe Experience Manager to address the DOM‑based XSS flaw.
  • Sanitise all user‑supplied data before rendering it in the browser, ensuring that data is encoded or escaped to prevent DOM manipulation.
  • Deploy a Web Application Firewall or equivalent controls to detect and block malicious script injections targeting Adobe Experience Manager instances.

Generated by OpenCVE AI on September 9, 2026 at 13:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T13:46:25.322Z

Reserved: 2026-08-10T11:07:19.627Z

Link: CVE-2026-72627

cve-icon Vulnrichment

Updated: 2026-09-11T13:39:22.895Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:01.250

Modified: 2026-09-11T14:17:32.783

Link: CVE-2026-72627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T13:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')