Junglewise Threat Intelligence

CVE-2026-48257: Adobe Experience Manager DOM-based XSS

CVE-2026-48257 · Severity: medium · CVSS 5.4 · Published 2026-07-14

Technologies: Adobe Experience Manager as a Cloud Service. Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to create and manage digital content and websites, is affected by a security vulnerability. An attacker could trick a user into visiting a malicious link, allowing the attacker to run unauthorized scripts in the user's web browser. This could lead to the theft of login session information or the unauthorized modification of content viewed by the user.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager. The flaw occurs when the application improperly neutralizes user-controlled input that is subsequently used to manipulate the Document Object Model (DOM) environment. An authenticated attacker with low privileges can exploit this by enticing a victim to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser session, potentially leading to session hijacking or unauthorized actions. The issue is resolved in Experience Manager as a Cloud Service 2026.6.0 and specific hotfixes for version 6.5.

Affected products

  • Adobe Experience Manager as a Cloud Service <= 2026.5.0
  • Adobe Experience Manager 6.5 LTS <= SP1
  • Adobe Experience Manager 6.5 <= 6.5.24

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References