Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run unauthorized scripts in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or webpage. If successful, this could lead to the theft of session information or the performance of unauthorized actions on behalf of the user within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw occurs when the application improperly neutralizes input that is subsequently used to update the Document Object Model (DOM) in the victim's browser. An attacker with low-privileged access can exploit this by sending a malicious link to a victim; when the victim interacts with the link, the attacker's JavaScript executes in the victim's session. This can lead to session hijacking or unauthorized data access. Adobe has addressed this in security bulletin APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory