CVE-2026-75639: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need before attempting exploitation?
The CVSS vector indicates that the attacker needs low privileges. Exploitation is network-accessible and has low attack complexity, but requires the victim to interact with a crafted webpage.
What impact could successful exploitation have?
Successful exploitation can execute malicious JavaScript in the victim's browser context. The CVSS vector indicates low confidentiality and integrity impact, no availability impact, and changed scope.