Junglewise Threat Intelligence

CVE-2026-75718: Adobe Experience Manager DOM-based XSS

CVE-2026-75718 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used enterprise content management and digital marketing platform, is affected by a DOM-based Cross-Site Scripting vulnerability. An attacker could trick a user into visiting a malicious webpage to execute arbitrary JavaScript in their browser, potentially stealing session tokens, credentials, or sensitive content being edited in Experience Manager.

Technical details

This is a DOM-based XSS vulnerability in Adobe Experience Manager where attacker-controlled input is reflected in the DOM without proper sanitization. The vulnerability requires user interaction—a victim must visit a crafted webpage or click a malicious link. An attacker can execute arbitrary JavaScript within the context of the victim's browser session, potentially leading to session hijacking, credential theft, or manipulation of Experience Manager content. The scope change suggests the vulnerability may affect components or assets beyond the immediate XSS context.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References