Junglewise Threat Intelligence

CVE-2026-71357: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-71357 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a widely-used content management system for enterprise web properties, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by an authorized user, executes arbitrary JavaScript in the victim's browser, potentially leading to session hijacking, credential theft, or unauthorized content modifications.

Technical details

This is a DOM-based cross-site scripting vulnerability in Adobe Experience Manager where an attacker can inject malicious JavaScript that is executed within the victim's browser context. The vulnerability requires user interaction—a victim must visit a crafted webpage—making it suitable for phishing or social engineering attacks. The XSS payload is processed through DOM manipulation rather than being reflected in the HTTP response, which can make it harder to detect with network-based protections. An authenticated attacker or a user with elevated privileges could potentially execute arbitrary JavaScript to access sensitive data, modify content, or perform administrative actions on behalf of the victim.

Affected products

  • Adobe Experience Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References