Executive brief
Adobe Experience Manager is a content management and digital marketing platform used by enterprises to create and manage web properties and customer experiences. A DOM-based cross-site scripting vulnerability allows attackers to inject malicious scripts that execute in users' browsers when they visit a crafted webpage, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the victim.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where untrusted data is used to dynamically modify the Document Object Model without proper sanitization. The vulnerability requires user interaction—a victim must visit an attacker-crafted webpage—but allows arbitrary JavaScript execution in the victim's browser context. Exploitation could result in session hijacking, defacement, or theft of sensitive information. The scope is changed, indicating the vulnerability can impact resources beyond the vulnerable component itself.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed