Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and customer experiences, is affected by a security vulnerability. An attacker could trick a user into visiting a malicious webpage, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of sensitive information or unauthorized actions being performed on behalf of the user within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw is rooted in improper neutralization of input during web page generation (CWE-79), specifically within the Document Object Model (DOM) environment. An attacker with low-privileged access can exploit this by convincing a victim to visit a specially crafted URL or webpage. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser session, potentially leading to session hijacking or unauthorized data access. Adobe has addressed this in security bulletin APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-56 published.