Junglewise Threat Intelligence

CVE-2026-75629: Adobe Experience Manager DOM-based XSS

CVE-2026-75629 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker can craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript code within their browser session, potentially allowing theft of session tokens, account takeover, or manipulation of content displayed to the victim.

Technical details

The vulnerability is a DOM-based cross-site scripting (XSS) issue in Adobe Experience Manager where attacker-controlled input is processed and rendered in the victim's DOM without proper sanitization. The attack vector requires user interaction—specifically, a victim must visit an attacker-crafted webpage or link. Once exploited, arbitrary JavaScript executes in the context of the victim's browser with the permissions of their Experience Manager session, allowing attacks against the victim's account or data. The scope is marked as changed, indicating the vulnerability can impact resources beyond the vulnerable component itself.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References