Junglewise Threat Intelligence

CVE-2026-72627: Adobe Experience Manager DOM-based XSS

CVE-2026-72627 · Severity: medium · CVSS 5.4 · Published 2026-09-08

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a content management and digital asset platform used by enterprises to build and manage web experiences, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the victim's browser within the context of Experience Manager, potentially leading to session hijacking, data theft, or credential compromise.

Technical details

This is a DOM-based XSS vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to execute malicious JavaScript within the victim's browser context. The vulnerability requires user interaction—specifically, a victim must visit a crafted webpage to trigger the exploit. The attack vector is network-based, and successful exploitation could result in arbitrary script execution, session compromise, or unauthorized access to sensitive data. Patches or mitigations should be available from Adobe; check their security advisories for updates.

Affected products

  • Adobe Experience Manager

Timeline

  • 2026-09-08: disclosed

References