Executive brief
Adobe Experience Manager, a popular web content management and digital asset platform used by enterprises, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by an Experience Manager user, executes arbitrary JavaScript in their browser session, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the user.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager that allows an attacker to execute arbitrary JavaScript in the victim's browser context. The vulnerability requires user interaction—specifically, the victim must visit a crafted webpage. DOM-based XSS occurs when untrusted data (typically from the URL or user input) is used unsafely to modify the page's DOM without proper sanitization. The scope change indicates that the vulnerability affects components or functionalities beyond the initially vulnerable code path. Remediation and patch availability information is not available from the provided advisory.
Affected products
- Adobe Experience Manager <UNKNOWN>
Timeline
- 2026-09-08: disclosed