Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and customer experiences, is affected by a security vulnerability. An attacker could trick a user into visiting a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of login tokens or the unauthorized performance of actions on behalf of the user within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, FP11.7 and earlier. The flaw resides in the improper neutralization of input during web page generation (CWE-79), allowing an attacker to manipulate the DOM environment. To exploit this, a remote attacker with low privileges must convince a victim to visit a specially crafted URL. Successful exploitation enables the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. Adobe has addressed this in security bulletin APSB26-34.
Affected products
- Adobe Experience Manager 6.5.24, FP11.7 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory