Executive brief
Adobe Experience Manager, a widely-used digital asset management and web content platform, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker can craft a malicious webpage that, when visited by an Experience Manager user, executes unauthorized JavaScript in their browser session, potentially leading to session hijacking, credential theft, or unauthorized actions within the platform.
Technical details
The vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager that allows an attacker to inject and execute malicious JavaScript by manipulating the DOM environment. The attack requires user interaction—a victim must visit an attacker-controlled or attacker-modified webpage. An unauthenticated attacker can exploit this to execute arbitrary JavaScript in the context of a victim's browser session with Experience Manager, potentially stealing session tokens, cookies, or performing unauthorized actions on behalf of the user.
Affected products
- Adobe Experience Manager <UNKNOWN>
Timeline
- 2026-09-08: disclosed