Executive brief
Adobe Experience Manager, a platform used to create and manage digital content and customer experiences, is vulnerable to DOM-based cross-site scripting (XSS). An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript in the browser, potentially leading to session hijacking, credential theft, or other client-side attacks.
Technical details
The vulnerability is a DOM-based cross-site scripting (XSS) issue in Adobe Experience Manager that allows attackers to manipulate the DOM environment and execute arbitrary JavaScript code within the victim's browser context. The attack requires user interaction—specifically, the victim must visit a crafted webpage. The scope is changed, indicating that the vulnerability can impact components or services beyond the vulnerable component itself. No patch information is currently available in the advisory.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed