Junglewise Threat Intelligence

CVE-2026-75647: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75647 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management and digital experience platform, is vulnerable to DOM-based cross-site scripting (XSS). An attacker could craft a malicious webpage that, when visited by an administrative or content editor user, executes unauthorized JavaScript code within their browser session, potentially allowing theft of session tokens, manipulation of published content, or unauthorized administrative actions.

Technical details

This DOM-based XSS vulnerability in Adobe Experience Manager allows an attacker to inject and execute malicious JavaScript by manipulating the DOM environment. The vulnerability requires user interaction—a victim must visit an attacker-controlled or compromised webpage that triggers the XSS payload. Successful exploitation occurs within the victim's browser context and changes the scope of access. The vulnerability is classified as medium severity with a CVSS score of 5.4. Patches or updates should be obtained from Adobe's official security advisory (APSB26-98).

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References