Executive brief
Adobe Experience Manager, a content management and digital asset platform used by enterprises to author and publish web content, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could trick a victim into visiting a malicious webpage, potentially allowing unauthorized execution of JavaScript code in the victim's browser session—potentially leading to credential theft, session hijacking, or unauthorized content modification.
Technical details
The vulnerability is a DOM-based cross-site scripting (XSS) flaw in Adobe Experience Manager resulting from improper handling of user-controlled input in the DOM environment. The attack vector is network-based and requires user interaction: a victim must visit an attacker-controlled or attacker-modified webpage. No authentication is required. An attacker can execute arbitrary JavaScript in the context of the victim's browser session, potentially compromising account credentials, session tokens, or sensitive data. The scope is noted as changed, indicating the vulnerability may affect other security properties beyond the component itself.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed