Executive brief
Adobe Experience Manager is a content management system used by enterprises to create and manage digital experiences across web and mobile. A DOM-based cross-site scripting vulnerability allows attackers to inject malicious JavaScript that executes in users' browsers when they visit a crafted webpage, potentially stealing session tokens, sensitive data, or performing unauthorized actions on behalf of the victim.
Technical details
The vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager that allows an attacker to manipulate the DOM environment and execute arbitrary JavaScript within the browser context of a victim. Exploitation requires user interaction—specifically, the victim must visit an attacker-controlled or attacker-modified webpage. The vulnerability results in a change of scope, meaning an attacker may be able to impact resources or privileges beyond the immediately affected component. DOM-based XSS vulnerabilities typically stem from unsafe handling of user-supplied input in client-side JavaScript code.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed