Junglewise Threat Intelligence

CVE-2026-47947: Adobe Experience Manager DOM-based XSS

CVE-2026-47947 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted web link. If successful, this could lead to the unauthorized access of session information or the performance of actions on behalf of the user.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw stems from improper neutralization of user-controlled input that is subsequently used to manipulate the Document Object Model (DOM) environment. An attacker with low-privileged access can exploit this by enticing a victim to visit a crafted URL, leading to the execution of arbitrary JavaScript in the victim's browser session. Because the vulnerability is scoped as 'Changed' (S:C), the script execution can impact components beyond the immediate vulnerable element, potentially allowing for session hijacking or unauthorized data access. Adobe has addressed this in security bulletin APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed: Initial publication of CVE-2026-47947
  • 2026-06-09: advisory: Adobe released security bulletin APSB26-56

References