Description
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Published: 2026-09-08
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DOM-based Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Adobe Experience Manager contains a DOM‑based cross‑site scripting flaw that lets an attacker inject and run malicious JavaScript in a victim’s browser session when the victim visits a carefully crafted URL or webpage. The vulnerability depends on the victim’s browser environment and does not allow arbitrary code execution on the server, but it can compromise user credentials, session data, or perform actions on behalf of the user. The flaw is identified as CWE‑79 and the description notes a change in scope, indicating that the impact may extend beyond the original user context.

Affected Systems

The affected products are Adobe Experience Manager 6.5, the 6.5 LTS release, and the cloud‑based Adobe Experience Manager as a Cloud Service. No additional version details are supplied, so all instances of these products are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.4 represents a moderate level of risk. The EPSS score is not available, which limits precise exploitation probability data, and the issue is not listed in CISA's KEV catalog. Because exploitation requires a victim to click or otherwise interact with a malicious page, the attack vector is user‑initiated. While the CVSS indicates moderate risk, the lack of publicly known exploits or KEV listing suggests the likelihood of widespread exploitation is currently low. Nonetheless, organizations should treat the vulnerability as a valid threat to user sessions and data integrity.

Generated by OpenCVE AI on September 9, 2026 at 09:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Security Update for Experience Manager 6.5, 6.5 LTS, and the cloud service to address the DOM‑based XSS flaw.
  • If a patch cannot be applied immediately, implement a Content Security Policy that restricts script sources to trusted origins and disables inline scripting to reduce the impact of XSS.
  • Review and block any known malicious URLs or patterns that may trigger the vulnerable code path, and monitor user reports of abnormal behavior in Experience Manager.

Generated by OpenCVE AI on September 9, 2026 at 09:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Title Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T13:27:17.943Z

Reserved: 2026-08-18T01:29:54.620Z

Link: CVE-2026-75715

cve-icon Vulnrichment

Updated: 2026-09-09T13:27:07.413Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:19.270

Modified: 2026-09-10T13:56:19.207

Link: CVE-2026-75715

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T10:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')