Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting that can execute malicious JavaScript in the victim’s browser
Action: Immediate Patch
AI Analysis

Impact

Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting vulnerability that allows an attacker to manipulate the Document Object Model of a victim’s browser and run arbitrary JavaScript. This can be used to steal session tokens, deface content, or perform other client‑side attacks. The flaw is triggered when a victim visits a specially crafted page, and it affects the scope of the application because the injected script can escape the original context.

Affected Systems

The vulnerability applies to Adobe Experience Manager 6.5, the 6.5 Long‑Term Support release, and the Adobe Experience Manager as a Cloud Service offering. The CVE entry does not list more granular patch versions, but the official advisory confirms that all current releases of these products are susceptible.

Risk and Exploitability

The CVSS score for this issue is 5.4, indicating moderate severity. No EPSS score is available, so the current exploitation probability is unknown, and the vulnerability is not present in the CISA KEV list. Exploitation requires user interaction—a victim must visit a malicious URL—making direct attacks dependent on social engineering or phishing. Given the scope change, the impact could extend beyond the original context if an attacker succeeds. Organizations should consider the vulnerability serious enough to warrant timely remediation.

Generated by OpenCVE AI on September 9, 2026 at 09:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Experience Manager security update or upgrade to a patched version as detailed in the Adobe advisory. This removes the DOM‑based XSS flaw entirely.
  • Where a patch is unavailable, enforce strict input validation and URL encoding on all user‑supplied data and deploy a Content Security Policy that blocks inline scripts. This mitigates the risk until a full fix can be applied.
  • Monitor web traffic and application logs for unusual script injection patterns, and update web application firewall rules to block known exploit payloads.

Generated by OpenCVE AI on September 9, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T15:00:14.266Z

Reserved: 2026-08-18T01:29:54.617Z

Link: CVE-2026-75679

cve-icon Vulnrichment

Updated: 2026-09-09T16:41:33.599Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:16.103

Modified: 2026-09-10T16:17:54.840

Link: CVE-2026-75679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')