Junglewise Threat Intelligence

CVE-2026-48262: Adobe Experience Manager DOM-based XSS

CVE-2026-48262 · Severity: medium · CVSS 5.4 · Published 2026-07-14

Technologies: Adobe Experience Manager as a Cloud Service. Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to execute malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted webpage. If successful, the attacker could potentially access sensitive information or perform actions on behalf of the user within the application.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Experience Manager. The flaw occurs when the application improperly neutralizes input that is subsequently used to manipulate the DOM environment. An attacker with low-privileged access can exploit this by enticing a victim to visit a malicious URL, leading to the execution of arbitrary JavaScript in the context of the victim's session. This vulnerability has a changed scope (S:C) because the script executes in the user's browser but can impact the security of the web application. Adobe has released updates to address this issue in AEM Cloud Service 2026.6.0 and specific hotfixes for version 6.5.

Affected products

  • Adobe Experience Manager as a Cloud Service <= 2026.5.0
  • Adobe Experience Manager 6.5 LTS <= SP1
  • Adobe Experience Manager 6.5 <= 6.5.24

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References