CVE-2026-75695: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need before attempting exploitation?
The vector specifies low privileges are required. Exploitation also requires the attacker to cause a victim to visit a crafted webpage.
What is the likely impact if exploitation succeeds?
Malicious JavaScript can execute in the victim's browser context. The stated impact includes low confidentiality and integrity effects, with no availability impact; the scope is changed.
Is exploitation fully remote and does it require user interaction?
The vulnerability is network-accessible with low attack complexity, but it is not silent: a victim must interact by visiting a crafted webpage.