Junglewise Threat Intelligence

CVE-2026-48251: Adobe Experience Manager DOM-based XSS

CVE-2026-48251 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security vulnerability. An attacker could trick a user into visiting a malicious link, allowing the attacker to run unauthorized scripts in the user's web browser. This could lead to the theft of session information or the performance of actions on behalf of the user within the application.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw occurs when the application improperly neutralizes user-controlled input that is subsequently used to modify the Document Object Model (DOM) in the victim's browser. An attacker can exploit this by convincing a logged-in user to visit a specially crafted URL. Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking or unauthorized data access. The vulnerability is tracked as CWE-79 and requires low privileges and user interaction.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References