Executive brief
Adobe Experience Manager, a widely-used content management system for building and managing enterprise websites, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could craft a malicious webpage that, when visited by an employee or administrator, injects harmful JavaScript code that executes in their browser session. This could lead to account takeover, data theft, or unauthorized changes to published website content.
Technical details
A DOM-based XSS vulnerability exists in Adobe Experience Manager where user-controlled input is improperly reflected in the DOM without sufficient sanitization. An attacker can craft a malicious URL or webpage that exploits this flaw to execute arbitrary JavaScript in the victim's browser with the privileges of the authenticated session. The attack vector is network-based and requires user interaction (the victim must visit or be tricked into visiting the malicious URL). The scope of the vulnerability is changed, indicating that an attacker may be able to impact resources beyond the vulnerable component itself. Patches are expected from Adobe via their security advisory APSB26-98.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed