Junglewise Threat Intelligence

CVE-2026-75724: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-75724 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management platform used to build and manage digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by a victim, executes unauthorized JavaScript code in the victim's browser within the context of Experience Manager. This could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.

Technical details

This is a DOM-based cross-site scripting vulnerability in Adobe Experience Manager that allows an attacker to inject and execute arbitrary JavaScript code in a victim's browser. The vulnerability exists in the DOM manipulation logic where user-controlled input is reflected without proper sanitization. Exploitation requires user interaction—specifically, the victim must visit or be redirected to a crafted webpage containing the malicious payload. The scope of the vulnerability is marked as changed, indicating potential impact beyond the immediate component. No information is currently available regarding patch availability or mitigation strategies.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References