Executive brief
Adobe Experience Manager, a widely-used content management platform, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript in the victim's browser within the context of Experience Manager. This could allow attackers to steal session credentials, impersonate users, or perform unauthorized actions on their behalf.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to inject and execute malicious JavaScript code. The vulnerability requires user interaction—a victim must be tricked into visiting an attacker-crafted webpage. The scope is changed, meaning the impact extends beyond the vulnerable component itself. Exploitation allows arbitrary JavaScript execution within the authenticated user's browser context. No information on patch availability was provided in the advisory.
Affected products
- Adobe Experience Manager <UNKNOWN>
Timeline
- 2026-09-08: disclosed