Junglewise Threat Intelligence

CVE-2026-75667: Adobe Experience Manager DOM-based XSS

CVE-2026-75667 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management system used by enterprises to create and manage digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could trick a user into visiting a malicious webpage to execute unauthorized JavaScript code in their browser session, potentially compromising account credentials or stealing sensitive information. The attack requires user interaction but could result in account takeover or data theft.

Technical details

This is a DOM-based XSS vulnerability in Adobe Experience Manager arising from improper handling of user-controlled input in the client-side DOM environment. The vulnerability allows an attacker to inject malicious JavaScript that executes within the victim's browser context under the application's security domain. Exploitation requires social engineering to trick a user into visiting a crafted webpage; no authentication is required to craft the malicious URL. An attacker can execute arbitrary JavaScript, steal session tokens, redirect users, or perform actions on behalf of the victim. No patch availability information is currently available in the advisory summary.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References