Executive brief
Adobe Experience Manager, a widely-used platform for managing digital content and customer experiences, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by an employee or customer, executes JavaScript code in their browser to steal session data, credentials, or perform unauthorized actions within Experience Manager.
Technical details
The vulnerability is a DOM-based XSS flaw in Adobe Experience Manager where user-supplied input is directly manipulated into the document object model without proper sanitization. An attacker can craft a malicious URL or webpage containing specially crafted payload that triggers JavaScript execution in the victim's browser within the security context of Experience Manager. Exploitation requires user interaction (the victim must visit the attacker's crafted webpage or click a malicious link). The scope impact is changed, meaning successful exploitation can affect resources beyond the vulnerable component. A patch from Adobe (APSB26-98) has been published.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed