Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or webpage. If successful, the attacker could potentially access sensitive information or perform actions on behalf of the user within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager. The flaw occurs when the application improperly neutralizes input that is subsequently used to manipulate the Document Object Model (DOM) environment. An attacker with low-privileged access can exploit this by sending a malicious link to a victim; when the victim interacts with the link, the attacker's script executes within the context of the victim's session. This can lead to session hijacking or unauthorized data access. The issue is resolved in AEM Cloud Service 2026.6.0 and specific hotfixes for version 6.5.
Affected products
- Adobe Experience Manager as a Cloud Service <= 2026.5.0
- Adobe Experience Manager 6.5 LTS <= SP1
- Adobe Experience Manager 6.5 <= 6.5.24
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory