Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted web link. If successful, this could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw stems from improper neutralization of user-controlled input that is subsequently used to modify the Document Object Model (DOM) environment in the victim's browser. An attacker with low-privileged access can exploit this by enticing a target user to interact with a malicious URL or crafted webpage. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking or unauthorized data access. Adobe has addressed this in newer versions of the software.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory