Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or webpage. If successful, this could allow the attacker to perform actions on behalf of the user or access sensitive information displayed within the application.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw stems from improper neutralization of input during web page generation (CWE-79), allowing an attacker to manipulate the DOM environment. An authenticated attacker with low privileges can exploit this by inducing a victim to interact with a malicious URL, leading to the execution of arbitrary JavaScript in the victim's browser context. Because the 'Scope' is changed (S:C), the impact can extend beyond the AEM application itself to other components within the browser's security boundary. Adobe has addressed this in security bulletin APSB26-56.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-56 published