Junglewise Threat Intelligence

CVE-2026-75636: Adobe Experience Manager DOM-based XSS

CVE-2026-75636 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used enterprise content management and digital marketing platform, is affected by a DOM-based Cross-Site Scripting vulnerability. An attacker can craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript in the victim's browser within the context of Experience Manager, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the victim.

Technical details

This is a DOM-based Cross-Site Scripting (XSS) vulnerability in Adobe Experience Manager. The vulnerability arises from improper handling of user-controlled input in the DOM environment, allowing attackers to inject and execute malicious JavaScript code. Exploitation requires user interaction—specifically, a victim must visit an attacker-controlled or compromised webpage. The vulnerability changes the scope, meaning the attacker can escape confinement and impact resources beyond the vulnerable component. An attacker can execute arbitrary JavaScript in the victim's browser session, potentially leading to session token theft, account compromise, or malicious actions performed on behalf of the authenticated user.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References