Executive brief
Adobe Experience Manager is a web content management system used by enterprises to create and manage digital experiences. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious JavaScript that executes in victims' browsers when they visit a crafted webpage, potentially enabling account takeover, session hijacking, or data theft.
Technical details
The vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager that allows an attacker to manipulate the DOM environment to execute arbitrary JavaScript within the security context of a victim's browser session. Exploitation requires user interaction—a victim must visit an attacker-controlled or compromised webpage containing the malicious payload. The impact includes potential unauthorized actions within the AEM instance, data exfiltration, or credential theft from authenticated users. A patch is expected to be available via Adobe's security bulletin APSB26-98.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed