Junglewise Threat Intelligence

CVE-2026-75690: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75690 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management and digital asset management platform, contains a DOM-based cross-site scripting vulnerability that allows attackers to inject malicious JavaScript code. An attacker could trick a user into visiting a crafted webpage to execute arbitrary scripts in the victim's browser, potentially leading to session hijacking, credential theft, or unauthorized actions within the application.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where attacker-controlled data is processed unsafely by client-side JavaScript code, allowing injection of arbitrary script execution. The vulnerability requires user interaction—a victim must visit a malicious webpage crafted by the attacker. The attack vector is network-based and occurs in the browser context, giving attackers the ability to execute arbitrary JavaScript with the privileges of the authenticated user. The scope is marked as changed, suggesting the impact extends beyond simple information disclosure.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References