Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DOM-based Cross‑Site Scripting enabling malicious JavaScript execution
Action: Patch
AI Analysis

Impact

The vulnerability is a DOM‑based Cross‑Site Scripting flaw in Adobe Experience Manager. Attackers can craft a webpage containing malicious JavaScript that, when a victim visits it, is executed by the victim’s browser in the context of the affected site. The flaw allows arbitrary script execution in the user’s browser session and can be used to steal credentials, hijack sessions, or deface content. The weakness is classified as CWE‑79.

Affected Systems

Adobe Experience Manager 6.5, the 6.5 LTS release, and the cloud‑based edition of Adobe Experience Manager are impacted. The specific affected versions are the default releases of these products, as listed by Adobe. System administrators should verify whether their installations correspond to these releases.

Risk and Exploitability

The CVSS score is 5.4, indicating moderate severity. The EPSS score is not available, so the exploitation likelihood remains uncertain, but the vulnerability requires end‑user interaction with a crafted page. It is not listed in CISA’s KEV catalog, suggesting no known active exploitation. Attackers would need to lure a user to visit a malicious URL; once the page loads, the script runs in the browser, potentially exposing sensitive data or user accounts.

Generated by OpenCVE AI on September 9, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for Adobe Experience Manager 6.5, 6.5 LTS, and the cloud edition as documented in Adobe’s security advisory.
  • Configure the web‑application firewall to block or sanitize URLs and query strings that can trigger the vulnerable DOM manipulation, limiting exposure of the affected vector.
  • Educate end users to avoid clicking on unknown or suspicious links and to verify URLs before visiting.

Generated by OpenCVE AI on September 9, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T13:24:50.718Z

Reserved: 2026-08-18T01:29:54.619Z

Link: CVE-2026-75705

cve-icon Vulnrichment

Updated: 2026-09-09T13:24:46.723Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:18.123

Modified: 2026-09-10T13:54:47.857

Link: CVE-2026-75705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')