Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and customer experiences, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted web link. If successful, this could allow the attacker to access sensitive information or perform actions on behalf of the user within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw stems from improper neutralization of input during web page generation (CWE-79), allowing an attacker to manipulate the DOM environment. Exploitation requires a remote attacker with low privileges to convince a victim to interact with a malicious link or webpage. Successful exploitation enables the execution of arbitrary JavaScript in the victim's browser session, potentially leading to session hijacking or unauthorized data access. Adobe has addressed this in security bulletin APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24 and earlier, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory