Executive brief
Adobe Experience Manager, a widely-used content management platform for digital asset creation and distribution, is vulnerable to a cross-site scripting (XSS) attack. An attacker can craft a malicious webpage that, when visited by a user, executes unauthorized code in their browser to steal session data, redirect users, or perform actions on their behalf within Experience Manager.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager that allows arbitrary JavaScript execution within the victim's browser context. The vulnerability arises from improper handling of user-controlled input in the DOM without adequate sanitization or encoding. Exploitation requires user interaction—a victim must visit a crafted webpage—but no authentication is needed. The attack can result in session hijacking, credential theft, or unauthorized modifications to digital assets and workflows. Adobe has released a security advisory (APSB26-98) with patch information, though the specific affected versions and mitigation details are not currently accessible.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed