CVE-2026-48257: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Published Jul 14, 2026
·Updated
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Affected Software
6 affected components
Adobe Adobe Experience Manager
Adobe Experience Manager<=6.5.25.0
Adobe Experience Manager<=2020.5.0
Adobe Experience Manager=6.5
Adobe Experience Manager=6.5-sp1
Adobe Experience Manager=6.5-sp2
Event History
Jul 14, 2026
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48257?
The severity of CVE-2026-48257 is medium with a CVSS score of 5.4.
2
What type of vulnerability is associated with CVE-2026-48257?
CVE-2026-48257 is a DOM-based Cross-Site Scripting (XSS) vulnerability.
3
How can CVE-2026-48257 be exploited?
An attacker can exploit CVE-2026-48257 by manipulating the DOM to execute malicious JavaScript in the victim's browser.
4
What software is affected by CVE-2026-48257?
CVE-2026-48257 affects Adobe Experience Manager.
5
What is required for successfully exploiting CVE-2026-48257?
Successful exploitation of CVE-2026-48257 requires user interaction.