Executive brief
Adobe Experience Manager, a widely-used content management platform for building web experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript code in the victim's browser within the context of Experience Manager, potentially leading to account hijacking, data theft, or unauthorized actions.
Technical details
This vulnerability is a DOM-based XSS flaw in Adobe Experience Manager that allows attackers to inject malicious JavaScript into the Document Object Model (DOM) environment. The attack requires user interaction—specifically, a victim must visit a crafted webpage—making it a reflected or stored XSS variant depending on the context. By manipulating the DOM, an attacker can execute arbitrary JavaScript within the browser's security context, potentially compromising session cookies, stealing credentials, or performing unauthorized operations. The scope is marked as changed, suggesting the vulnerability can impact resources beyond the vulnerable component itself.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed