Executive brief
Adobe Experience Manager, a content management platform used by enterprises to create and publish digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the victim's browser within the Experience Manager context, potentially enabling account takeover, data theft, or unauthorized actions.
Technical details
This vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager. The root cause involves improper handling of DOM manipulation, allowing an attacker to inject malicious JavaScript code. Exploitation requires user interaction; a victim must visit a crafted webpage to trigger the vulnerability. The attacker gains code execution in the victim's browser session, potentially enabling session hijacking, credential theft, or malicious actions within the AEM environment. A patch is expected to be available via Adobe's security advisory APSB26-98.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed