Junglewise Threat Intelligence

CVE-2026-75717: Adobe Experience Manager DOM-based XSS

CVE-2026-75717 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management system used for building and managing digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by a user, executes JavaScript code in the victim's browser within the context of Experience Manager, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the victim.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager. The vulnerability allows an attacker to manipulate the DOM environment to inject and execute malicious JavaScript in the context of a victim's browser. Exploitation requires user interaction—specifically, a victim must visit a crafted webpage controlled by the attacker. The scope is changed, indicating the vulnerability can impact resources beyond the vulnerable component itself. No patch information is available at this time.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References