Executive brief
Adobe Experience Manager, a widely-used digital asset and content management platform, is affected by a DOM-based cross-site scripting (XSS) vulnerability. An attacker could craft a malicious webpage that, when visited by a victim, executes arbitrary JavaScript in the user's browser within the context of Experience Manager, potentially allowing unauthorized actions, session hijacking, or data theft.
Technical details
This is a DOM-based XSS vulnerability in Adobe Experience Manager where untrusted user input is processed and rendered in the DOM without proper sanitization, allowing an attacker to inject and execute arbitrary JavaScript. The vulnerability requires user interaction—a victim must be tricked into visiting a crafted webpage. The impact includes potential unauthorized actions in the victim's session, data exfiltration, or privilege escalation depending on the victim's permissions. Patch availability is indicated by the APSB26-98 security bulletin reference, though the specific version ranges and patch details are not accessible in the provided materials.
Affected products
- Adobe Experience Manager
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: APSB26-98 security bulletin issued