Executive brief
Adobe Experience Manager, a content management system used to create and manage digital experiences, contains a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a user, executes unauthorized JavaScript in their browser to steal credentials, deface content, or perform actions on their behalf. Exploitation requires the victim to visit the attacker's webpage while logged into Experience Manager.
Technical details
The vulnerability is a DOM-based XSS flaw in Adobe Experience Manager where user-supplied input is improperly sanitized before being rendered in the DOM, allowing an attacker to inject and execute arbitrary JavaScript. The attack vector is network-based and requires user interaction—specifically, a victim must visit a crafted webpage while authenticated to the target system. An attacker can execute malicious script in the context of the victim's browser session, potentially leading to session hijacking, credential theft, or unauthorized administrative actions. The CVSS score of 5.4 indicates medium severity with changed scope.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed