Executive brief
Adobe Experience Manager, a widely-used content management platform for enterprises, is vulnerable to DOM-based cross-site scripting (XSS). An attacker could craft a malicious webpage that, when visited by a user, executes arbitrary JavaScript in their browser within the context of Experience Manager, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the victim.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager. The vulnerability is exploited by manipulating the DOM environment to execute malicious JavaScript within the victim's browser context. Exploitation requires user interaction—a victim must visit a crafted webpage to trigger the attack. The scope of the vulnerability is changed, indicating potential for impact beyond the vulnerable component itself. No patch availability information is currently available from the provided advisory.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed