Junglewise Threat Intelligence

CVE-2026-72626: Adobe Experience Manager DOM-based cross-site scripting

CVE-2026-72626 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management platform used by enterprises to create and manage digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker can craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript in the victim's browser within the context of Experience Manager, potentially allowing account compromise or unauthorized actions.

Technical details

The vulnerability is a DOM-based cross-site scripting flaw in Adobe Experience Manager that arises from improper sanitization of user-controlled input used in DOM manipulation. An attacker crafts a malicious URL or webpage containing XSS payload that targets the application's client-side JavaScript logic. Successful exploitation requires user interaction—the victim must visit the attacker-crafted webpage while authenticated or in a context where the XSS executes. The scope is reported as changed, indicating the vulnerability can impact resources beyond the vulnerable component. Patches or mitigations are likely available through Adobe's security advisory APSB26-98.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed: Published on NVD

References