Junglewise Threat Intelligence

CVE-2026-48250: Adobe Experience Manager DOM-based XSS

CVE-2026-48250 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security vulnerability. An attacker could use this flaw to run unauthorized scripts in a user's web browser if the user is tricked into visiting a malicious link. This could lead to the theft of session information or unauthorized actions being performed on behalf of the user within the application.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw is caused by improper neutralization of input during web page generation (CWE-79), allowing an attacker to manipulate the DOM environment. To exploit this, a remote attacker with low privileges must convince a victim to interact with a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. Adobe has addressed this in security bulletin APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe security bulletin APSB26-56 published.

References