Junglewise Threat Intelligence

CVE-2026-48261: Adobe Experience Manager DOM-based XSS

CVE-2026-48261 · Severity: medium · CVSS 5.4 · Published 2026-07-14

Technologies: Adobe Experience Manager as a Cloud Service. Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run unauthorized scripts in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or webpage. If successful, this could lead to the unauthorized access of session information or the performance of actions on behalf of the user.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager. The flaw stems from improper neutralization of input that is subsequently used to manipulate the DOM environment. An attacker with low-privileged access can exploit this by convincing a victim to visit a crafted URL, leading to the execution of arbitrary JavaScript within the context of the victim's browser session. This can result in session hijacking or unauthorized data modification. The issue is resolved in Experience Manager as a Cloud Service version 2026.6.0 and specific hotfixes for version 6.5.

Affected products

  • Adobe Experience Manager as a Cloud Service <= 2026.5.0
  • Adobe Experience Manager 6.5 LTS <= SP1
  • Adobe Experience Manager 6.5 <= 6.5.24

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats