Junglewise Threat Intelligence

CVE-2026-19644: Adobe Experience Manager DOM-based XSS

CVE-2026-19644 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform for building digital experiences, contains a DOM-based cross-site scripting (XSS) flaw. An attacker could craft a malicious webpage that, when visited by an AEM user, injects malicious JavaScript to steal session credentials, manipulate content, or perform unauthorized actions on behalf of the victim.

Technical details

The vulnerability is a DOM-based XSS flaw in Adobe Experience Manager resulting from improper handling of untrusted input in the client-side DOM environment. An attacker can craft a malicious URL or webpage that, when clicked or visited by a victim, causes malicious JavaScript to execute within the AEM interface context. Exploitation requires user interaction (a victim must visit the crafted page). The DOM scope is altered, allowing attackers to access and manipulate sensitive data or perform actions. No patch information is currently available from Adobe's security advisory (access was denied).

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References