Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DOM-based Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to execute malicious JavaScript in the victim's browser. The flaw arises when untrusted input is processed directly in the document object model, enabling manipulation of page content. An attacker can exploit this by delivering a specially crafted URL that a user must click on, causing the injected script to run with the privileges of the current user session.

Affected Systems

The affected products are Adobe Experience Manager 6.5, the 6.5 LTS release, and the cloud‑service variant. No other editions were listed as vulnerable. The flaw exists across all these releases and does not appear restricted by configuration.

Risk and Exploitability

The CVSS score is 5.4, indicating moderate severity. The exploit requires user interaction and a crafted link; no evidence of widespread exploitation is reported, and the vulnerability is not in CISA’s KEV catalog. The absence of an EPSS score means the exact likelihood is unknown, but user‑click required attacks can still pose a threat, especially in environments where users can visit arbitrary URLs.

Generated by OpenCVE AI on September 9, 2026 at 09:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Experience Manager to the latest patch or version that addresses the DOM‑based XSS vulnerability as detailed in the Adobe security advisory.
  • Configure a strong content‑security‑policy that restricts inline scripts and disallows script sources from external domains unless explicitly trusted.
  • Deploy a web application firewall or similar defenses that detect and block suspicious DOM manipulation patterns or cross‑site scripting payloads.

Generated by OpenCVE AI on September 9, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T14:00:38.497Z

Reserved: 2026-08-18T01:29:54.617Z

Link: CVE-2026-75678

cve-icon Vulnrichment

Updated: 2026-09-09T14:00:32.613Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:15.977

Modified: 2026-09-10T13:52:35.377

Link: CVE-2026-75678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T09:45:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')