Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (DOM‑based XSS)
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that can lead to arbitrary JavaScript execution in the victim’s browser context. An attacker could manipulate the web page’s Document Object Model to inject malicious script without the need for server‑side code changes. Based on the description, it is inferred that the attack vector involves manipulating the DOM environment of a crafted webpage, requiring the victim to intentionally visit that page. The impact is the ability of the attacker to steal session cookies, deface pages, or execute further attacks on the user’s behalf. The flaw is identified as CWE‑79 and requires the victim to intentionally visit a crafted page, making it a user‑interaction vulnerability with scope changes in the affected applications.

Affected Systems

Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are affected. No specific patch versions are indicated, but all versions listed by Adobe fall under the scope of the vulnerability.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity, reflecting the need for user interaction and the limited impact beyond the victim’s browser. EPSS is not available, so current exploitation probability cannot be quantified; the flaw is not listed in the CISA KEV catalog. Attackers would need to host or embed malicious content that targets the vulnerable DOM handling of Experience Manager. Because the exploit requires victim interaction, it is less likely to spread automatically but still poses a risk where users are susceptible to phishing or malicious links.

Generated by OpenCVE AI on September 9, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe's latest security patch for Experience Manager 6.5 and the Cloud Service as soon as it becomes available
  • Implement a Content Security Policy that disallows inline JavaScript and restricts script sources
  • Validate and encode all user‑controlled input before it is inserted into the DOM to prevent script injection

Generated by OpenCVE AI on September 9, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T13:12:05.549Z

Reserved: 2026-08-18T01:29:54.617Z

Link: CVE-2026-75675

cve-icon Vulnrichment

Updated: 2026-09-09T13:11:59.071Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:15.747

Modified: 2026-09-10T13:57:35.520

Link: CVE-2026-75675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:30:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')