Executive brief
Adobe Experience Manager, a widely-used content management and digital asset platform, contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to execute malicious JavaScript code in a victim's browser. An attacker must trick a user into visiting a specially crafted webpage to exploit this issue. Successful exploitation could lead to session hijacking, credential theft, or data theft from within the user's authenticated session.
Technical details
This is a DOM-based XSS vulnerability (CWE-79) in Adobe Experience Manager where an attacker can manipulate the DOM environment to inject and execute arbitrary JavaScript within the victim's browser context. The vulnerability requires user interaction—a victim must visit an attacker-controlled or attacker-modified webpage—but does not require prior authentication to the target system. Successful exploitation grants an attacker the ability to perform actions on behalf of the victim, access sensitive data, or modify page content. The scope is changed, indicating the vulnerability affects security properties beyond the vulnerable component itself.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed