Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to execute malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link. If successful, the attacker could potentially access sensitive information or perform actions on behalf of the user within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager. The flaw occurs when the application improperly neutralizes user-controlled input that is subsequently used to modify the Document Object Model (DOM) in the victim's browser. An attacker with low-privileged network access can exploit this by inducing a user to interact with a malicious URL. Successful exploitation allows for the execution of arbitrary JavaScript in the victim's browser session, potentially leading to session hijacking or unauthorized data access. The issue is resolved in AEM Cloud Service 2026.6.0 and specific hotfixes for version 6.5.
Affected products
- Adobe Adobe Experience Manager as a Cloud Service <= 2026.5.0
- Adobe Adobe Experience Manager 6.5 LTS <= SP1
- Adobe Adobe Experience Manager 6.5 <= 6.5.24
Timeline
- 2026-07-14: advisory
- 2026-07-14: disclosed