Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site Scripting (DOM-based)
Action: Patch
AI Analysis

Impact

Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting vulnerability that allows an attacker to execute malicious JavaScript in the victim's browser by manipulating the DOM environment. Exploitation requires the victim to visit a crafted webpage, and the flaw changes the scope of the affected context, enabling the attacker to perform actions in the context of the authenticated user. The impact is the potential compromise of session data, credential theft, or the execution of additional malicious payloads.

Affected Systems

Adobe Experience Manager versions 6.5, 6.5 LTS, and the Adobe Experience Manager as a Cloud Service are affected.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, suggesting low to moderate exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attacks are client‑side and require user interaction with a malicious link or page. The lack of a widespread exploit indicates a lower risk, but the compromised context can be abused if the user is a privileged actor.

Generated by OpenCVE AI on September 9, 2026 at 12:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Experience Manager patch released in the APSB26‑98 advisory
  • Upgrade to the latest 6.5 LTS version available from Adobe
  • If immediate upgrade is not feasible, sanitize or encode all user‑supplied parameters that influence DOM manipulation

Generated by OpenCVE AI on September 9, 2026 at 12:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T13:14:05.848Z

Reserved: 2026-08-18T01:29:54.616Z

Link: CVE-2026-75669

cve-icon Vulnrichment

Updated: 2026-09-09T13:13:59.539Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:15.137

Modified: 2026-09-10T13:57:38.917

Link: CVE-2026-75669

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:15:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')