Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and customer experiences, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or webpage. If successful, this could lead to the unauthorized access of session information or the performance of actions on behalf of the user within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager. The flaw occurs when the application improperly neutralizes input that is subsequently used to manipulate the DOM environment in the victim's browser. An attacker with low-privileged network access can exploit this by inducing a user to interact with a malicious URL. Successful exploitation allows the execution of arbitrary JavaScript within the context of the victim's session, potentially leading to session hijacking or unauthorized data exfiltration. The vulnerability affects versions 6.5.24, LTS SP1, and 2026.04 and earlier.
Affected products
- Adobe Experience Manager 6.5.24 and earlier, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe published security bulletin APSB26-56