Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that allows an attacker to inject and execute malicious JavaScript in the victim's browser. The flaw requires that a user visit a crafted page, with the attacker manipulating the document object model to override client‑side logic. Once executed, the attacker can read or modify page contents, steal session cookies, or perform actions on behalf of the user, thereby violating confidentiality and integrity in a client‑side context.

Affected Systems

Adobe Experience Manager 6.5, 6.5 LTS, and the Cloud Service edition are all affected. Specific patched versions are not listed in the data, so any installation of these editions should consider applying the Adobe Security Bulletin APSB26‑98 fix.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate impact risk. EPSS data is not available, and the vulnerability is not listed in the KEV catalog, suggesting no widespread current exploitation. The attack vector is client‑side and requires user interaction – the victim must visit a maliciously crafted URL or click a link. Exploitation would likely occur through social engineering or by embedding the payload in a trusted domain that the user visits.

Generated by OpenCVE AI on September 9, 2026 at 12:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe AEM patch documented in APSB26‑98 to all affected instances.
  • Restrict user input by enabling Adobe's built‑in XSS filtering or adding server‑side input sanitization to prevent script injection in untrusted fields.
  • Deploy a Content Security Policy that blocks inline scripts and only allows scripts from trusted origins, and monitor for anomalous script execution via web‑application firewall logs.

Generated by OpenCVE AI on September 9, 2026 at 12:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T13:25:21.937Z

Reserved: 2026-08-18T01:29:54.615Z

Link: CVE-2026-75660

cve-icon Vulnrichment

Updated: 2026-09-09T13:25:16.209Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:14.543

Modified: 2026-09-11T12:37:39.623

Link: CVE-2026-75660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:15:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')