Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting (DOM-based XSS)
Action: Assess Impact
AI Analysis

Impact

Adobe Experience Manager is affected by a DOM-based Cross‑Site Scripting vulnerability. An attacker can manipulate the DOM environment to execute malicious JavaScript within the victim's browser. This requires the user to visit a crafted web page, meaning exploitation depends on user interaction. The flaw can alter the content served to the victim, allowing phishing, credential theft, or other client‑side attacks.

Affected Systems

Vulnerable versions include Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. The documentation does not specify precise patch levels, so any release listed by Adobe as susceptible should be treated as affected until an official fix is applied.

Risk and Exploitability

The CVSS base score of 5.4 indicates moderate severity, while the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires user interaction and there is no publicly known exploit, the likelihood of attack is moderate. The attacker’s potential impact is confined to the victim’s browser session, but may still enable credential compromise and phishing. The absence of a commercial exploit reduces immediate risk, yet the DOM‑based XSS nature and the need for social engineering still warrant timely remediation.

Generated by OpenCVE AI on September 9, 2026 at 14:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update issued by Adobe for Experience Manager 6.5, 6.5 LTS, and the Cloud Service as described in Adobe’s security advisory https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html.
  • Implement a Content Security Policy that blocks inline scripts and restricts JavaScript execution to trusted sources, thereby mitigating the impact of any remaining DOM manipulation.
  • Enforce user training and awareness so that users understand the risk of visiting untrusted URLs and verify site certificates before interacting with potentially malicious content.

Generated by OpenCVE AI on September 9, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T16:07:15.766Z

Reserved: 2026-08-18T01:29:54.618Z

Link: CVE-2026-75693

cve-icon Vulnrichment

Updated: 2026-09-09T16:07:11.447Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:17.143

Modified: 2026-09-10T13:52:57.137

Link: CVE-2026-75693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T14:15:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')