Executive brief
Adobe Experience Manager, a widely-used content management and digital marketing platform, contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts. An attacker could craft a malicious webpage that, when visited by an authorized user, executes arbitrary JavaScript in the user's browser session, potentially enabling account compromise, data theft, or further attacks on the organization.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager where attacker-controlled input is used to manipulate the browser's document object model without proper sanitization. The vulnerability requires user interaction—a victim must be tricked into visiting a crafted webpage while authenticated to Experience Manager. Exploitation allows arbitrary JavaScript execution in the context of the victim's browser, which could lead to session hijacking, credential theft, or unauthorized actions on behalf of the user. The vulnerability has a CVSS score of 5.4 (medium severity) and the scope is marked as changed, indicating potential impact beyond the vulnerable component itself.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed