Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DOM-based XSS that allows arbitrary JavaScript execution in the victim’s browser, potentially leading to data exposure or session hijacking
Action: Patch
AI Analysis

Impact

Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting flaw that lets an attacker craft malicious input, causing the browser to execute arbitrary JavaScript in the victim’s session. This vulnerability can compromise the confidentiality and integrity of user data and enable attackers to hijack sessions or exfiltrate information. Exploitation requires the victim to open a crafted page, so the attack vector is a browser‑based user interaction.

Affected Systems

The flaw impacts Adobe Experience Manager 6.5, including the 6.5 LTS release, and the Adobe Experience Manager as a Cloud Service offering. No additional version details are supplied.

Risk and Exploitability

The CVSS score is 5.4, indicating moderate severity. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. The flaw requires user interaction with a crafted webpage, making it a client‑side XSS. The changed scope in the CVSS vector implies that the vulnerability can affect confidentiality and integrity, but no evidence of privilege escalation is provided. Overall risk is moderate, and patching is recommended.

Generated by OpenCVE AI on September 9, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor‑supplied patch or upgrade to a version that incorporates the fix.
  • If a patch is not yet available, enforce a strict Content Security Policy or use a Web Application Firewall to block execution of unsolicited JavaScript.
  • As a temporary measure, remove or sanitize any untrusted user‑supplied URLs or referrer‑based content that feeds the vulnerable code path.

Generated by OpenCVE AI on September 9, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T15:01:17.958Z

Reserved: 2026-08-18T01:29:54.619Z

Link: CVE-2026-75702

cve-icon Vulnrichment

Updated: 2026-09-09T16:41:52.574Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:17.893

Modified: 2026-09-10T16:17:55.160

Link: CVE-2026-75702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:30:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')