Executive brief
Adobe Experience Manager, a widely-used content management and digital asset management platform, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker can trick users into visiting a malicious webpage to execute unauthorized JavaScript code in their browser, potentially leading to session hijacking, credential theft, or manipulation of content and user data within Experience Manager.
Technical details
The vulnerability is a DOM-based cross-site scripting (XSS) flaw that allows an attacker to manipulate the Document Object Model environment and execute arbitrary JavaScript code within a victim's browser context. Exploitation requires user interaction—a victim must visit a crafted webpage or click a malicious link. The vulnerability changes scope, meaning an attacker can potentially escape the normal security boundaries of the application. The attack vector is network-based and no authentication is required on the attacker's side to craft the malicious payload.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed