CVE-2026-75657: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to manipulate the DOM environment and induce a victim to visit a crafted webpage. The CVSS vector indicates that the attacker also requires low-level privileges, although the provided data does not specify what those privileges are.
What impact could successful exploitation have?
Malicious JavaScript can execute in the context of the victim's browser. The stated impact is low confidentiality and integrity impact, with no availability impact; the scope is changed.
How can we tell whether users may be affected?
Users may be exposed if they visit a crafted webpage that triggers the vulnerable DOM behavior in Adobe Experience Manager. The provided information does not include affected versions, configuration conditions, detection indicators, or workaround guidance.