Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to execute malicious code in a user's web browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or website. If successful, the attacker could potentially access sensitive information or perform actions on behalf of the user within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw allows a remote attacker with low privileges to execute arbitrary JavaScript in the victim's browser by manipulating the Document Object Model (DOM) environment. Exploitation requires user interaction, specifically that a victim visits a malicious URL or crafted webpage. The vulnerability affects AEM as a Cloud Service (<= 2026.5.0), AEM 6.5 LTS (<= SP1), and AEM 6.5 (<= 6.5.24). Adobe has released updates (2026.6.0 and specific hotfixes) to remediate this issue.
Affected products
- Adobe Adobe Experience Manager as a Cloud Service <= 2026.5.0
- Adobe Adobe Experience Manager 6.5 LTS <= SP1
- Adobe Adobe Experience Manager 6.5 <= 6.5.24
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory