Executive brief
Adobe Experience Manager, a content management platform used by enterprises to create and manage digital experiences, is vulnerable to a DOM-based cross-site scripting (XSS) attack. An attacker could trick a user into visiting a malicious webpage that executes JavaScript code within the user's browser session, potentially allowing the attacker to steal session credentials, modify page content, or perform unauthorized actions on behalf of the victim.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where an attacker manipulates the DOM environment to execute malicious JavaScript within the victim's browser context. The vulnerability requires user interaction—specifically, a victim must visit an attacker-crafted webpage to trigger exploitation. The attack changes the scope of the vulnerability, allowing the attacker to affect resources or operations beyond the vulnerable component itself. Patches or mitigations are available from Adobe; see APSB26-98.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed