Junglewise Threat Intelligence

CVE-2026-75725: Adobe Experience Manager DOM-based XSS

CVE-2026-75725 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management platform used by enterprises to create and manage digital experiences, is vulnerable to DOM-based cross-site scripting (XSS). An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript code within their browser session. This could lead to unauthorized access to the victim's Experience Manager account, theft of sensitive content, or manipulation of published digital properties.

Technical details

A DOM-based cross-site scripting vulnerability exists in Adobe Experience Manager where user-supplied input is improperly processed in the DOM environment without adequate sanitization. The vulnerability requires user interaction—specifically that a victim must visit a crafted webpage controlled by the attacker. Upon exploitation, arbitrary JavaScript can be executed in the victim's browser within the security context of Experience Manager, potentially allowing attackers to perform actions as the victim, steal session tokens, or exfiltrate data. The scope of the vulnerability has been noted as changed, which may indicate impacts beyond confidentiality.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References