CVE-2026-48294
published 2026-06-17CVE-2026-48294: Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could…
PriorityP340high7.4CVSS 3.1
AVNACLPRNUIRSCCHINAN
EPSS
0.72%
49.6th percentile
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 26.5.2.2 | — |
| adobe | adobe_acrobat_pdf_extension | <= 26.5.2.2 | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
cvelistv5v3.17.4HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Acrobat PDF Extension up to 26.5.2.2 URL cross site scripting
vuldb·2026-06-29·CVSS 7.4
CVE-2026-48294 [HIGH] Adobe Acrobat PDF Extension up to 26.5.2.2 URL cross site scripting
A vulnerability was found in Adobe Acrobat PDF Extension up to 26.5.2.2 and classified as problematic. This affects an unknown function of the component URL Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2026-48294. It is possible to launch the attack remotely. No exploit is available.
GHSA
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability.
ghsa_unreviewed·2026-06-17
CVE-2026-48294 [HIGH] CWE-79 Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability.
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
CVEList
CVE-2026-48294: Adobe Acrobat PDF Extension (Chrome) versions 26
cvelistv5·2026-06-16·CVSS 7.4
CVE-2026-48294 [HIGH] CWE-79 CVE-2026-48294: Adobe Acrobat PDF Extension (Chrome) versions 26
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-17
Published