Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (DOM‑based XSS)
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager is affected by a DOM‑based Cross‑Site Scripting vulnerability that enables an attacker to inject and execute malicious JavaScript in the victim’s browser. The flaw arises from improper sanitization of data used to manipulate the Document Object Model, allowing the injection of client‑side code. This is a classic input‑validation weakness identified as CWE‑79 and can compromise confidentiality, integrity, or availability of the user’s session if the malicious script performs phishing, credential theft, or further exploitation. The vulnerability is scoped to the user’s browser context and requires user interaction to trigger, meaning that simply hosting content does not automatically provide an attack surface.

Affected Systems

The affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No specific sub‑versions are listed, but all releases under the 6.5 umbrella are considered vulnerable until patched. The vulnerability is documented for the core product and the cloud‑based deployment model, so both on‑premises and SaaS customers must verify installation dates and update status.

Risk and Exploitability

The recorded CVSS score is 5.4, indicating moderate severity with a requirement for user interaction. EPSS data is not available, so the exploitation likelihood cannot be quantified, but the absence of a KEV listing suggests it is not a currently widely exploited issue. The attack vector is inferred to be web‑based, requiring a victim to download or open a crafted webpage that manipulates the DOM to load malicious JavaScript. The scope change in the description implies the impact is limited to the victim’s browser session, not system‑wide privileges.

Generated by OpenCVE AI on September 9, 2026 at 09:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Experience Manager patch that addresses the DOM‑based XSS flaw, as published in the Adobe security advisory
  • Review all client‑side scripts and input handling mechanisms in your AEM deployments to ensure proper sanitization of user‑supplied data before DOM manipulation
  • Perform security testing focused on client‑side injection points, including fuzzing of URL parameters and form fields, to confirm the patch has removed the vulnerability

Generated by OpenCVE AI on September 9, 2026 at 09:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T21:26:35.450Z

Reserved: 2026-08-18T01:29:54.619Z

Link: CVE-2026-75706

cve-icon Vulnrichment

Updated: 2026-09-11T21:26:28.893Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:18.240

Modified: 2026-09-11T22:16:41.163

Link: CVE-2026-75706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T09:45:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')