CVE-2026-48261: Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48261?
The severity of CVE-2026-48261 is rated as medium, with a CVSS score of 5.4.
How do I fix CVE-2026-48261?
To fix CVE-2026-48261, apply the latest security updates and patches provided by Adobe for Adobe Experience Manager.
What type of vulnerability is CVE-2026-48261?
CVE-2026-48261 is a DOM-based Cross-Site Scripting (XSS) vulnerability.
What are the potential impacts of CVE-2026-48261?
Exploitation of CVE-2026-48261 could allow an attacker to execute malicious JavaScript in the victim's browser.
Does CVE-2026-48261 require user interaction for exploitation?
Yes, exploitation of CVE-2026-48261 requires user interaction to manipulate the DOM environment.