Junglewise Threat Intelligence

CVE-2026-75678: Adobe Experience Manager DOM-based XSS

CVE-2026-75678 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform for building web experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript code in the victim's browser within the context of Experience Manager, potentially leading to account hijacking, data theft, or unauthorized actions.

Technical details

This vulnerability is a DOM-based XSS flaw in Adobe Experience Manager that allows attackers to inject malicious JavaScript into the Document Object Model (DOM) environment. The attack requires user interaction—specifically, a victim must visit a crafted webpage—making it a reflected or stored XSS variant depending on the context. By manipulating the DOM, an attacker can execute arbitrary JavaScript within the browser's security context, potentially compromising session cookies, stealing credentials, or performing unauthorized operations. The scope is marked as changed, suggesting the vulnerability can impact resources beyond the vulnerable component itself.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References