Junglewise Threat Intelligence

CVE-2026-71356: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-71356 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management and digital asset platform, contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to execute malicious JavaScript code in a victim's browser. An attacker must trick a user into visiting a specially crafted webpage to exploit this issue. Successful exploitation could lead to session hijacking, credential theft, or data theft from within the user's authenticated session.

Technical details

This is a DOM-based XSS vulnerability (CWE-79) in Adobe Experience Manager where an attacker can manipulate the DOM environment to inject and execute arbitrary JavaScript within the victim's browser context. The vulnerability requires user interaction—a victim must visit an attacker-controlled or attacker-modified webpage—but does not require prior authentication to the target system. Successful exploitation grants an attacker the ability to perform actions on behalf of the victim, access sensitive data, or modify page content. The scope is changed, indicating the vulnerability affects security properties beyond the vulnerable component itself.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References