Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link. If successful, the attacker could potentially access sensitive information or perform actions on behalf of the user within the application.
Technical details
Adobe Experience Manager is vulnerable to a DOM-based Cross-Site Scripting (XSS) flaw (CWE-79). The vulnerability exists due to improper neutralization of user-controlled input before it is used to update the Document Object Model (DOM) in the victim's browser. An attacker with low-privileged network access can exploit this by enticing a user to interact with a malicious URL or webpage. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking or unauthorized data access. The issue is addressed in AEM Cloud Service 2026.6.0 and specific hotfixes for version 6.5.
Affected products
- Adobe Experience Manager as a Cloud Service <= 2026.5.0
- Adobe Experience Manager 6.5 LTS <= SP1
- Adobe Experience Manager 6.5 <= 6.5.24
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory