Junglewise Threat Intelligence

CVE-2026-75670: Adobe Experience Manager DOM-based XSS

CVE-2026-75670 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management and digital experience platform, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could trick a user into visiting a malicious webpage, allowing them to execute arbitrary JavaScript in the victim's browser and potentially steal sensitive data, hijack sessions, or perform actions on behalf of the victim within Experience Manager.

Technical details

This is a DOM-based XSS vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to execute arbitrary JavaScript within the context of a victim's browser session. The vulnerability requires user interaction—a victim must visit a crafted webpage—but does not require the victim to be authenticated. The attack occurs on the client-side through DOM manipulation, meaning the malicious payload is processed by the browser's JavaScript engine. Successful exploitation allows an attacker to perform actions within the scope of the victim's session, including credential theft, session hijacking, and unauthorized modifications to Experience Manager content.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References