Junglewise Threat Intelligence

CVE-2026-34625: Adobe Experience Manager DOM-based XSS

CVE-2026-34625 · Severity: medium · CVSS 5.4 · Published 2026-04-14

Technologies: Adobe Experience Manager Screens. Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security flaw that could allow an attacker to execute malicious code in a user's web browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or website. If successful, the attacker could potentially steal session information or perform actions on behalf of the user within the application.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, FP11.7 and earlier. The flaw stems from improper neutralization of input during web page generation (CWE-79), allowing an attacker to manipulate the DOM environment. Exploitation requires a network-based attacker with low privileges to trick a victim into interacting with a crafted webpage (User Interaction: Required). Successful exploitation enables the execution of arbitrary JavaScript within the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. Adobe has addressed this in security bulletin APSB26-34.

Affected products

  • Adobe Experience Manager 6.5.24, FP11.7 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory

References

Related threats