Junglewise Threat Intelligence

CVE-2026-75639: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75639 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a web content management platform used by enterprises to create and manage digital experiences, is vulnerable to DOM-based cross-site scripting (XSS). An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the victim's browser with access to their session and data. This could lead to account compromise, data theft, or unauthorized actions performed on behalf of the victim.

Technical details

Adobe Experience Manager contains a DOM-based cross-site scripting vulnerability where user-supplied input is reflected in the DOM without proper sanitization. The vulnerability requires user interaction—a victim must visit a crafted webpage or link—but no authentication is required. Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially stealing session cookies, performing actions as the victim, or accessing sensitive data. The scope is changed, indicating the vulnerability can impact other resources or systems beyond the vulnerable component itself. A patch is available through Adobe security advisory APSB26-98.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: Adobe security advisory APSB26-98

References