Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security flaw that could allow an attacker to run unauthorized scripts in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or webpage. If successful, this could allow the attacker to access sensitive information or perform actions on behalf of the user within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw stems from improper neutralization of input during web page generation (CWE-79), allowing an attacker to manipulate the DOM environment. An attacker with low privileges can exploit this by convincing a victim to visit a malicious URL, leading to the execution of arbitrary JavaScript in the victim's browser context. Because the vulnerability is 'Scope Changed' (S:C), the impact can extend beyond the AEM application itself to the user's browser session. Adobe has addressed this in APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory