Junglewise Threat Intelligence

CVE-2026-47982: Adobe Experience Manager DOM-based XSS

CVE-2026-47982 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's web browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or website. If successful, this could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw resides in the improper neutralization of input during web page generation (CWE-79), allowing an attacker to manipulate the Document Object Model (DOM) environment. Exploitation requires a low-privileged attacker to trick a victim into interacting with a malicious URL or crafted webpage. Successful exploitation enables the execution of arbitrary JavaScript in the victim's browser session, which can lead to session hijacking or unauthorized data access. Adobe has addressed this in APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References