Junglewise Threat Intelligence

CVE-2026-19479: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-19479 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management platform used to build and manage digital experiences, is affected by a DOM-based cross-site scripting (XSS) vulnerability. An attacker could trick a user into visiting a malicious webpage to execute arbitrary JavaScript in their browser session, potentially leading to account compromise, data theft, or unauthorized actions within Experience Manager.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where an attacker manipulates the Document Object Model (DOM) environment to inject and execute malicious JavaScript code within the victim's browser context. The vulnerability requires user interaction—specifically, the victim must visit a crafted webpage—but does not require authentication. Exploitation allows an attacker to execute arbitrary scripts within the security context of the user's browser session, potentially leading to session hijacking, credential theft, or unauthorized administrative actions. The scope of the vulnerability is changed, indicating it affects confidentiality or integrity beyond the vulnerable component itself.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References