Executive brief
Adobe Experience Manager, a widely-used content management and digital experience platform, contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to execute malicious scripts in a victim's browser. An attacker would need to trick a user into visiting a crafted webpage to trigger the vulnerability. If exploited, this could lead to account takeover, session hijacking, or theft of sensitive information stored in the browser context.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to execute arbitrary JavaScript in the victim's browser context. The vulnerability requires user interaction—specifically, a victim must visit an attacker-controlled or compromised webpage. The vulnerability changes scope, meaning the attacker can potentially access resources or data beyond the immediate XSS payload. Fixes and patch availability should be verified via Adobe's official security advisory (APSB26-98).
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed