Junglewise Threat Intelligence

CVE-2026-48255: Adobe Experience Manager DOM-based XSS

CVE-2026-48255 · Severity: medium · CVSS 5.4 · Published 2026-07-14

Technologies: Adobe Experience Manager as a Cloud Service. Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to execute malicious code in a user's web browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or website. If successful, the attacker could potentially access sensitive information or perform actions on behalf of the user within the application.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) due to improper neutralization of input during web page generation (CWE-79). The flaw allows a remote attacker with low privileges to execute arbitrary JavaScript in the victim's browser by manipulating the Document Object Model (DOM) environment. Exploitation requires user interaction, specifically that a victim visits a malicious URL or crafted webpage. The vulnerability affects AEM as a Cloud Service (<= 2026.5.0), AEM 6.5 LTS (<= SP1), and AEM 6.5 (<= 6.5.24). Adobe has released updates (2026.6.0 and specific hotfixes) to remediate this issue.

Affected products

  • Adobe Adobe Experience Manager as a Cloud Service <= 2026.5.0
  • Adobe Adobe Experience Manager 6.5 LTS <= SP1
  • Adobe Adobe Experience Manager 6.5 <= 6.5.24

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats