Junglewise Threat Intelligence

CVE-2026-75708: Adobe Experience Manager DOM-based Cross-Site Scripting

CVE-2026-75708 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management and digital marketing platform, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker can craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the victim's browser within the context of Experience Manager, potentially leading to session hijacking, credential theft, or unauthorized content manipulation.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager. The vulnerability exists in the client-side JavaScript code that processes user input without proper sanitization, allowing an attacker to inject malicious scripts that execute in the victim's browser within the Experience Manager context. Exploitation requires user interaction (the victim must visit a crafted webpage containing the exploit). The scope is changed, meaning the vulnerability impacts resources beyond the vulnerable component itself. Attackers can execute arbitrary JavaScript, potentially stealing sessions, stealing credentials, or modifying content.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References