Junglewise Threat Intelligence

CVE-2026-48268: Adobe Experience Manager DOM-based XSS

CVE-2026-48268 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or webpage. If successful, this could allow the attacker to perform actions on behalf of the user or access sensitive information displayed within the application.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw stems from improper neutralization of input during web page generation (CWE-79), allowing an attacker to manipulate the DOM environment. An authenticated attacker with low privileges can exploit this by inducing a victim to interact with a malicious URL, leading to the execution of arbitrary JavaScript in the victim's browser context. Because the 'Scope' is changed (S:C), the impact can extend beyond the AEM application itself to other components within the browser's security boundary. Adobe has addressed this in security bulletin APSB26-56.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe security bulletin APSB26-56 published

References