Executive brief
Adobe Experience Manager, a widely-used content management platform, contains a DOM-based cross-site scripting (XSS) vulnerability that could allow attackers to execute malicious code in the browsers of users who visit a specially crafted webpage. This vulnerability requires user interaction and could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim within Experience Manager.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to execute arbitrary JavaScript in the victim's browser context. The vulnerability requires user interaction—specifically, a victim must visit a crafted webpage. The scope is changed, indicating a potential impact beyond the vulnerable component itself. No information on available patches or workarounds is currently available from the provided reference materials.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed