SB2026071511 - Multiple vulnerabilities in Adobe Experience Manager Screens
Published: July 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 13 vulnerabilities.
1) Cross-site scripting (CVE-ID: CVE-2026-48255)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when processing DOM content in the browser. A remote user can cause malicious script execution to execute arbitrary code.
User interaction is required to trigger the malicious script.
2) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-48259)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to server-side request forgery in Adobe Experience Manager when handling requests. A remote user can send a specially crafted request to execute arbitrary code.
3) Cross-site scripting (CVE-ID: CVE-2026-48263)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when rendering stored content. A remote user can inject a malicious script into stored content to execute arbitrary code.
User interaction is required to trigger the malicious script. This issue only affects indicated AEMaaCS releases.
4) Path traversal (CVE-ID: CVE-2026-48310)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in Adobe Experience Manager when handling file access requests. A remote attacker can send a specially crafted request to disclose sensitive information.
This issue only affects indicated AEMaaCS releases.
5) Cross-site scripting (CVE-ID: CVE-2026-48355)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when rendering stored content. A remote user can inject a malicious script into stored content to execute arbitrary code.
User interaction is required to trigger the malicious script. This issue only affects indicated AEMaaCS releases.
6) XML External Entity injection (CVE-ID: CVE-2026-48359)
CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper restriction of xml external entity reference in Adobe Experience Manager when parsing XML input. A remote user can submit crafted XML content to execute arbitrary code.
7) Cross-site scripting (CVE-ID: CVE-2026-48253)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when processing DOM content in the browser. A remote user can cause malicious script execution to execute arbitrary code.
User interaction is required to trigger the malicious script.
8) Cross-site scripting (CVE-ID: CVE-2026-48254)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when processing DOM content in the browser. A remote user can cause malicious script execution to execute arbitrary code.
User interaction is required to trigger the malicious script.
9) Missing Authentication for Critical Function (CVE-ID: CVE-2026-48252)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
The vulnerability allows a remote attacker to bypass security features.
The vulnerability exists due to missing authentication for critical function in Adobe Experience Manager when handling requests. A remote attacker can access a critical function without authentication to bypass security features.
This issue only affects indicated AEMaaCS releases.
10) Cross-site scripting (CVE-ID: CVE-2026-48257)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when processing DOM content in the browser. A remote user can cause malicious script execution to execute arbitrary code.
User interaction is required to trigger the malicious script.
11) Cross-site scripting (CVE-ID: CVE-2026-48260)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when processing DOM content in the browser. A remote user can cause malicious script execution to execute arbitrary code.
User interaction is required to trigger the malicious script.
12) Cross-site scripting (CVE-ID: CVE-2026-48261)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when processing DOM content in the browser. A remote user can cause malicious script execution to execute arbitrary code.
User interaction is required to trigger the malicious script.
13) Cross-site scripting (CVE-ID: CVE-2026-48262)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when processing DOM content in the browser. A remote user can cause malicious script execution to escalate privileges.
User interaction is required to trigger the malicious script.
Remediation
Install update from vendor's website.