Executive brief
Adobe Experience Manager, a widely-used content management and digital experience platform, contains a DOM-based cross-site scripting (XSS) vulnerability that allows attackers to inject malicious code. An attacker could craft a malicious webpage that, when visited by an Experience Manager user, executes arbitrary JavaScript in their browser session, potentially leading to account compromise, credential theft, or unauthorized actions within the platform.
Technical details
This is a DOM-based cross-site scripting (XSS) vulnerability in Adobe Experience Manager where an attacker can manipulate the Document Object Model (DOM) environment to execute malicious JavaScript code within the victim's browser. The vulnerability requires user interaction—a victim must visit or be directed to a crafted webpage for exploitation to occur. The vulnerability changes the scope, suggesting it may allow an attacker to affect resources or functionality beyond the vulnerable component itself. Successful exploitation can lead to session hijacking, credential theft, or unauthorized administrative actions within Experience Manager.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed