Cross-site scripting in Adobe Experience Manager - CVE-2026-48355
Published: July 15, 2026
Adobe Experience Manager
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in Adobe Experience Manager when rendering stored content. A remote user can inject a malicious script into stored content to execute arbitrary code.
User interaction is required to trigger the malicious script. This issue only affects indicated AEMaaCS releases.