Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (DOM‑based XSS)
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject and execute arbitrary JavaScript in the victim’s browser when the victim visits a malicious webpage. The vulnerability is exploited by manipulating the page’s Document Object Model; no local privileges are required and the attackers need only entice a user to click a crafted link. Once executed, the attacker can steal session cookies, read or modify page content, and perform actions on behalf of the user. The CVSS rating of 5.4 indicates a moderate risk to confidentiality, integrity and availability, with the primary impact being client‑side compromise rather than server compromise.

Affected Systems

Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS and Adobe Experience Manager as a Cloud Service are affected. The vulnerability remains in all supported releases of these products.

Risk and Exploitability

The exploit requires user interaction, so broader penetration depends on social engineering or delivery via phishing. The EPSS score is not available, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no mass‑mode exploitation has been observed. However, the CVSS score of 5.4 and the requirement for a victim‑to‑visit a crafted page imply a realistic risk for targeted attacks, especially in environments where users frequently open emails or visit external sites.

Generated by OpenCVE AI on September 9, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe security advisory patch for Experience Manager 6.5 and 6.5 LTS immediately
  • For the Cloud Service, verify that the latest security updates are applied via the Adobe Admin Console
  • Educate users to avoid clicking suspicious links and encourage safe browsing practices

Generated by OpenCVE AI on September 9, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T15:00:03.176Z

Reserved: 2026-08-18T01:29:54.618Z

Link: CVE-2026-75694

cve-icon Vulnrichment

Updated: 2026-09-09T16:41:31.833Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:17.267

Modified: 2026-09-10T16:17:55.050

Link: CVE-2026-75694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T14:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')