CVE-2026-48294
HIGHAdobe Acrobat Pdf Extension (Chrome) < 26.5.2.2 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Title source: ruleDescription
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
References (1)
Core 1
Scores
CVSS v3
7.4
EPSS
0.0059
EPSS Percentile
43.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
adobe/acrobat
< 26.5.2.2
Adobe/Adobe Acrobat PDF Extension (Chrome)
< 26.5.2.2
Published
Jun 17, 2026
Tracked Since
Jun 17, 2026