Executive brief
Adobe Experience Manager, a web content management platform used to build and manage digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker can craft a malicious webpage that, when visited by a user, executes unauthorized JavaScript code in the victim's browser, potentially allowing session hijacking, credential theft, or unauthorized actions within Experience Manager.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to inject and execute malicious JavaScript. The vulnerability requires user interaction—specifically that a victim must visit a crafted webpage—making it suitable for phishing or social engineering attacks. The scope is changed, indicating the vulnerability can affect resources beyond the vulnerable component itself. The attack vector is network-based and occurs client-side in the victim's browser context.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed