Impact
Adobe Experience Manager is vulnerable to a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject and execute arbitrary JavaScript in the victim’s browser context. The flaw is triggered when a user visits a specially constructed webpage, after which the product’s client‑side code processes input that an attacker can control. If the attack succeeds, the script runs with the permissions of the victim’s browser session, potentially enabling the attacker to manipulate page content or interact with other web resources.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and all earlier releases are affected. The issue exists in the core front‑end handling of the application and can be triggered by any user who can view a maliciously crafted page.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity. Because exploitation requires user interaction (the victim must visit a crafted URL), the risk is confined to situations where users access untrusted content. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The change in scope suggests that, if exploited, the impact could extend beyond the initial user context, but no evidence of privilege escalation is provided.
OpenCVE Enrichment