CVE-2026-19479: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Event History
Frequently Asked Questions
What access and conditions are required to exploit this issue?
An attacker needs low-level privileges and must induce a victim to visit a crafted webpage. The attack is network-reachable and has low complexity, but it requires user interaction.
What could successful exploitation allow?
Successful exploitation can execute malicious JavaScript in the victim's browser context. The reported impact includes limited confidentiality and integrity effects, and the scope change indicates the vulnerable component can affect resources beyond its own security authority.