Executive brief
Adobe Experience Manager, a content management and digital asset platform used by enterprises to build and manage web experiences, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the victim's browser within the context of Experience Manager, potentially leading to session hijacking, data theft, or credential compromise.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to execute malicious JavaScript within the victim's browser context. The vulnerability requires user interaction—specifically, a victim must visit a crafted webpage to trigger the exploit. The attack vector is network-based, and successful exploitation could result in arbitrary script execution, session compromise, or unauthorized access to sensitive data. Patches or mitigations should be available from Adobe; check their security advisories for updates.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed