CVE-2026-48294

Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:adobe:acrobat:*:*:*:*:*:chrome:*:*

History

17 Jun 2026, 16:58

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 10:55

Updated : 2026-06-29 17:17


NVD link : CVE-2026-48294

Mitre link : CVE-2026-48294

CVE.ORG link : CVE-2026-48294


JSON object : View

Products Affected

adobe

  • acrobat
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')