Junglewise Threat Intelligence

CVE-2026-75722: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75722 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform for building digital experiences, is vulnerable to DOM-based cross-site scripting (XSS). An attacker could craft a malicious webpage that, when visited by an Experience Manager user, executes arbitrary JavaScript in their browser and potentially compromises their account or sensitive data managed within the platform.

Technical details

The vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager. The root cause involves unsafe manipulation of the DOM environment that allows an attacker to inject and execute arbitrary JavaScript code within the victim's browser context. Exploitation requires user interaction—specifically, a victim must visit an attacker-controlled webpage. The flaw changes the attack scope, potentially allowing the attacker to impact resources outside of the vulnerable component itself. A successful exploit could result in session hijacking, credential theft, or unauthorized modifications to content managed within Experience Manager.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References