Junglewise Threat Intelligence

CVE-2026-34624: Adobe Experience Manager DOM-based XSS

CVE-2026-34624 · Severity: medium · CVSS 5.4 · Published 2026-04-14

Technologies: Adobe Experience Manager Screens. Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used for managing digital content and assets, is vulnerable to a security flaw that allows malicious scripts to run in a user's browser. To exploit this, an attacker must trick a logged-in user into visiting a specially crafted website. If successful, the attacker could potentially access sensitive session information or perform actions on behalf of the user within the application.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, FP11.7 and earlier. The flaw resides in the improper neutralization of input during web page generation (CWE-79), allowing an attacker to manipulate the DOM environment. Exploitation requires a remote attacker with low privileges to convince a victim to interact with a malicious link or webpage (User Interaction required). Successful exploitation enables the execution of arbitrary JavaScript in the victim's browser session, which can lead to session hijacking or unauthorized data access. Adobe has addressed this in newer versions, and users are advised to update to the latest available patches.

Affected products

  • Adobe Experience Manager 6.5.24, FP11.7 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory

References

Related threats