Executive brief
Adobe Experience Manager, a widely-used content management and digital experience platform, is vulnerable to DOM-based cross-site scripting (XSS). An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in their browser within the context of Experience Manager, potentially stealing session tokens, credentials, or sensitive data.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where an attacker can manipulate the DOM environment to execute malicious JavaScript code. The vulnerability requires user interaction—specifically, a victim must visit or be redirected to a crafted webpage—to be exploited. The scope is reported as changed, indicating the vulnerability may affect confidentiality, integrity, or availability beyond the vulnerable component itself. A patch is likely available via Adobe's security bulletins (APSB26-98), though the advisory link is currently inaccessible.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed