CVE-2026-75678: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to attempt exploitation?
The severity vector indicates network reachability, low attack complexity, and low privileges are required. Exploitation also requires a victim to interact with attacker-controlled content by visiting a crafted webpage.
What is the expected security impact if exploitation succeeds?
The supplied severity vector rates confidentiality and integrity impact as low, with no availability impact. It also marks scope as changed, indicating the impact crosses the vulnerable component's authorization boundary.