Executive brief
Adobe Experience Manager, a content management platform used by enterprises to create and manage digital experiences, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker could trick a user into visiting a malicious webpage to execute JavaScript code in their browser, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the victim.
Technical details
A DOM-based XSS vulnerability exists in Adobe Experience Manager where untrusted user input is processed and used to manipulate the browser's Document Object Model without proper sanitization. The vulnerability requires user interaction (visiting a crafted webpage) to be exploited. An attacker can inject and execute arbitrary JavaScript code within the security context of the victim's browser session, potentially allowing account compromise or data theft. The scope is changed, indicating the vulnerability may impact resources beyond the vulnerable component itself.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed