Junglewise Threat Intelligence

CVE-2026-48271: Adobe Experience Manager DOM-based XSS

CVE-2026-48271 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security vulnerability that could allow an attacker to run malicious code in a user's browser. To exploit this, an attacker would need to trick a logged-in user into visiting a specially crafted link or webpage. If successful, this could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager (AEM) versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw occurs when the application improperly neutralizes input that is subsequently used to manipulate the DOM environment. An attacker with low-level privileges can exploit this by convincing a victim to interact with a malicious URL, leading to the execution of arbitrary JavaScript within the context of the victim's browser session. This vulnerability is tracked as CWE-79 and has a CVSS 3.1 base score of 5.4, reflecting that the 'Scope' is changed (S:C) because the script executes in the client's browser environment rather than the server.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References