Executive brief
Adobe Experience Manager, a content management system used by enterprises to create and manage digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the victim's browser within the Experience Manager context, potentially allowing unauthorized access to sensitive content or session hijacking.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager that occurs when malicious input is processed and reflected in the DOM without proper sanitization. The vulnerability requires user interaction—a victim must visit a crafted webpage to trigger the attack. An attacker can manipulate the DOM environment to execute arbitrary JavaScript code within the victim's browser session, potentially leading to credential theft, session hijacking, or unauthorized actions performed on behalf of the victim. The scope of impact has been changed, indicating an expanded attack surface. A patch or mitigation from Adobe should be available via their security advisory APSB26-98.
Affected products
- Adobe Experience Manager <UNKNOWN>
Timeline
- 2026-09-08: disclosed: CVE-2026-75701 published