Executive brief
Adobe Experience Manager, a web content management platform used by enterprises to build and manage digital experiences, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by an authorized user, executes malicious JavaScript in the user's browser session, potentially allowing unauthorized access to sensitive content or actions within Experience Manager.
Technical details
The vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager. The attack requires user interaction—specifically, a victim must visit a crafted webpage—but does not require prior authentication to the target system. An attacker can manipulate the DOM environment to execute arbitrary JavaScript within the context of a logged-in user's browser session. The scope is marked as changed, indicating the vulnerability may affect security properties beyond the vulnerable component. This is a known issue tracked as CVE-2026-75716 with an assigned CVSS score of 5.4 (medium severity).
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed