Executive brief
Adobe Experience Manager, a widely-used content management and digital asset platform, contains a DOM-based cross-site scripting (XSS) vulnerability that could allow attackers to execute malicious scripts in users' browsers. An attacker would need to trick a user into visiting a specially crafted webpage to trigger the vulnerability. A successful exploit could compromise user sessions, steal sensitive data, or perform unauthorized actions on behalf of the victim.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to execute arbitrary JavaScript code within the victim's browser context. The vulnerability requires user interaction—a victim must visit an attacker-controlled or compromised webpage containing a crafted payload. The scope is changed, indicating the vulnerability may affect confidentiality, integrity, or availability beyond the vulnerable component itself. No patch availability information is provided in the advisory.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed