Cross-site scripting in Adobe Experience Manager - CVE-2026-48263

 

Cross-site scripting in Adobe Experience Manager - CVE-2026-48263

Published: July 15, 2026


Vulnerability identifier: #VU137615
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-48263
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to cross-site scripting in Adobe Experience Manager when rendering stored content. A remote user can inject a malicious script into stored content to execute arbitrary code.

User interaction is required to trigger the malicious script. This issue only affects indicated AEMaaCS releases.


Affected software

Adobe Experience Manager

How to mitigate CVE-2026-48263

Install security update from vendor's website.

Adobe Experience Manager - addressed in versions 6.5.25.0.43971, 2026.6.0

External References

Related Security Bulletins