Junglewise Threat Intelligence

CVE-2026-19713: Adobe Experience Manager DOM-based XSS

CVE-2026-19713 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management platform for digital asset creation and distribution, is vulnerable to a cross-site scripting (XSS) attack. An attacker can craft a malicious webpage that, when visited by a user, executes unauthorized code in their browser to steal session data, redirect users, or perform actions on their behalf within Experience Manager.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager that allows arbitrary JavaScript execution within the victim's browser context. The vulnerability arises from improper handling of user-controlled input in the DOM without adequate sanitization or encoding. Exploitation requires user interaction—a victim must visit a crafted webpage—but no authentication is needed. The attack can result in session hijacking, credential theft, or unauthorized modifications to digital assets and workflows. Adobe has released a security advisory (APSB26-98) with patch information, though the specific affected versions and mitigation details are not currently accessible.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References