Junglewise Threat Intelligence

CVE-2026-75713: Adobe Experience Manager DOM-based XSS

CVE-2026-75713 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager is a web content management platform used by enterprises to create and manage digital experiences. A DOM-based cross-site scripting vulnerability allows an attacker to execute malicious code in a victim's browser if they visit a specially crafted webpage, potentially leading to session hijacking, credential theft, or defacement of web pages.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where user-controlled input is processed and executed within the DOM without proper sanitization. The vulnerability requires user interaction—specifically, the victim must visit an attacker-controlled or compromised webpage containing the malicious payload. An attacker can exploit this to execute arbitrary JavaScript in the victim's browser context, potentially stealing session tokens, credentials, or performing actions on behalf of the user. The scope change indicates the vulnerability may affect components or functionality beyond the directly vulnerable feature.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References