Executive brief
Adobe Experience Manager, a content management and digital experience platform used by enterprises to build and manage websites and applications, is vulnerable to DOM-based cross-site scripting (XSS). An attacker can trick users into visiting a malicious webpage that executes arbitrary JavaScript in their browser within the context of Experience Manager, potentially leading to session hijacking, credential theft, or unauthorized actions on behalf of the victim.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager that allows execution of arbitrary JavaScript code in a victim's browser. The vulnerability requires user interaction—a victim must visit a crafted webpage to trigger the exploit. The attack manipulates the DOM environment to inject and execute malicious scripts within the security context of the Experience Manager application. Scope is marked as changed, indicating the vulnerability may affect resources beyond the vulnerable component itself. A patch is expected to be available via Adobe security bulletin APSB26-98.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed