Executive brief
Adobe Experience Manager, a widely-used content management platform for enterprise websites, is affected by a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a user, executes unauthorized JavaScript code in the victim's browser session, potentially allowing theft of session credentials or malicious actions on the user's behalf.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager that allows an attacker to inject malicious JavaScript through manipulation of the DOM environment. Exploitation requires user interaction—specifically, the victim must visit a crafted webpage. The vulnerability changes the scope of the attack, meaning an attacker may be able to affect other users or components beyond the immediate target. No patch information is available from the provided advisory details.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed