Executive brief
Adobe Experience Manager, a widely-used content management and digital marketing platform, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by an authenticated user, executes arbitrary JavaScript in their browser to steal credentials, deface content, or perform actions on their behalf within Experience Manager.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager that allows execution of arbitrary JavaScript within the victim's browser context. The vulnerability requires user interaction—specifically, the victim must visit a crafted webpage. The attack manipulates the DOM environment to inject and execute malicious scripts. The scope is changed, indicating the impact extends beyond simple information disclosure. Patches or mitigations are expected from Adobe; refer to APSB26-98 for official guidance.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed