Executive brief
Adobe Experience Manager, a content management platform used to build and manage digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by an Experience Manager user, executes arbitrary JavaScript in their browser, potentially leading to account compromise, session hijacking, or theft of sensitive content.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager that allows an attacker to inject malicious JavaScript into the Document Object Model. The vulnerability is triggered when a victim visits a crafted webpage while authenticated or using the vulnerable component. An attacker can execute arbitrary JavaScript in the victim's browser context, potentially stealing session tokens, credentials, or sensitive data, or performing actions on behalf of the user. User interaction is required for exploitation. Patch availability should be verified through Adobe's official security advisory.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed