DOM-Based Cross-Site Scripting Vulnerability in Adobe Experience Manager
CVE-2026-75661

5.4MEDIUM

What is CVE-2026-75661?

Adobe Experience Manager is vulnerable to a DOM-based Cross-Site Scripting (XSS) flaw that allows attackers to execute malicious JavaScript within the victim's browser. This vulnerability occurs when user interaction leads to the manipulation of the Document Object Model (DOM), allowing unauthorized scripts to run in the context of the user's session. Exploiting this vulnerability necessitates that victims visit a specially crafted webpage, which can result in various security risks including data theft and unauthorized actions performed in the context of the user.

Affected Version(s)

Adobe Experience Manager 6.5 0 <= 6.5.24

Adobe Experience Manager 6.5 LTS 0

Adobe Experience Manager as a Cloud Service 0 <= 2026.7.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.