Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‐Site Scripting (DOM‑based)
Action: Patch
AI Analysis

Impact

Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject and execute malicious JavaScript in a victim's browser. The flaw requires the victim to load a crafted page, after which the attacker’s code runs in the context of the user, potentially stealing credentials, session tokens or performing actions on behalf of the user.

Affected Systems

The vulnerability impacts Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. All installations of these products are affected unless the vendor’s security update (APSB26‑98) is applied.

Risk and Exploitability

With a CVSS score of 5.4 and no EPSS data, the risk is moderate, and the flaw has not been listed in the CISA KEV catalogue. Exploitation requires user interaction—an attacker must provide a link or embedded page that a victim visits, leading to execution of JavaScript in the victim’s browser. The scope change indicates that the vulnerability can affect the overall application behavior within the browser environment.

Generated by OpenCVE AI on September 9, 2026 at 12:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the update documented in Adobe’s APSB26‑98 advisory to all affected Experience Manager 6.5, 6.5 LTS, and Cloud Service instances.
  • Implement a strict Content Security Policy that disallows inline script execution and restricts script sources to trusted domains to mitigate the XSS risk until the patch is in place.
  • Run automated XSS scans against the application after the patch to confirm the DOM‑based vulnerability has been removed.

Generated by OpenCVE AI on September 9, 2026 at 12:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T13:46:26.099Z

Reserved: 2026-08-18T01:29:54.613Z

Link: CVE-2026-75639

cve-icon Vulnrichment

Updated: 2026-09-11T13:39:33.277Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:13.200

Modified: 2026-09-11T14:17:33.190

Link: CVE-2026-75639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')