Junglewise Threat Intelligence

CVE-2026-75693: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75693 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management platform used to create and manage digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker can craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the victim's browser within the context of their Experience Manager session, potentially allowing account takeover or unauthorized actions.

Technical details

The vulnerability is a DOM-based cross-site scripting (XSS) flaw where unsanitized user input is processed and reflected in the DOM environment, allowing injection of malicious JavaScript. The attack requires user interaction—a victim must visit a crafted webpage containing the malicious payload. When executed, the attacker's script runs with the privileges of the authenticated user in their browser context. The scope of impact has been changed according to the advisory. Patches or mitigations should be checked against Adobe's official security bulletin APSB26-98.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References