Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DOM‑Based Cross‑Site Scripting (XSS)
Action: Timely Patch
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that is triggered when a victim visits a specially crafted URL. The attacker manipulates the browser’s document object model to inject and execute malicious JavaScript within the victim’s context, executing client‑side code execution. Successful exploitation does not require server‑side changes.

Affected Systems

Affected systems include Adobe Experience Manager version 6.5, the 6.5 LTS release, and the as‑a‑Cloud‑Service deployment. The vulnerability is present across these product lines but no specific patch or version numbers are listed beyond the general product identifiers.

Risk and Exploitability

The CVSS score of 5.4 places the flaw in the medium severity range. EPSS score is not available, and the issue is not currently listed in CISA’s KEV catalog. Exploitation requires user interaction: a victim must click a malicious link or visit a crafted page. The change in scope indicates a broader impact, but the exact components remain unspecified.

Generated by OpenCVE AI on September 9, 2026 at 13:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe security update for Experience Manager released in the August 2026 advisory linked above
  • Sanitize all user‑supplied data that may be reflected in the DOM before it is rendered
  • Configure a robust Content Security Policy to block inline script execution and mitigate the impact of XSS

Generated by OpenCVE AI on September 9, 2026 at 13:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-11T13:46:25.628Z

Reserved: 2026-08-18T01:29:54.620Z

Link: CVE-2026-75709

cve-icon Vulnrichment

Updated: 2026-09-11T13:39:26.896Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:18.577

Modified: 2026-09-11T14:17:33.670

Link: CVE-2026-75709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T19:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')