Executive brief
Adobe Experience Manager, a widely-used platform for managing digital content and customer experiences, is affected by a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in their browser within the context of the Experience Manager application, potentially allowing theft of session tokens, customer data manipulation, or unauthorized actions on behalf of the victim.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where attacker-controlled input is processed and reflected in the DOM without proper sanitization or encoding. The vulnerability requires user interaction—a victim must be tricked into visiting a crafted webpage—making it a reflected/client-side XSS variant. An authenticated or unauthenticated attacker can inject malicious JavaScript that executes in the victim's browser session, potentially leading to session hijacking, credential theft, or unauthorized actions. The CVSS score of 5.4 (medium) reflects the requirement for user interaction and the changed scope. Patches are expected to be available through Adobe's security bulletins (APSB26-98).
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed