
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48294 is a Universal Cross-Site Scripting (UXSS)-class cross-origin data disclosure vulnerability in the Adobe Acrobat PDF Extension for Chrome. It affects versions 26.5.2.2 and earlier of the browser extension, allowing attackers to access sensitive session data across origins. The vulnerability was published on June 17, 2026, and assigned a CVSS v3.1 base score of 7.4 (High) (Feedly, EUVD).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting) and stems from improper origin validation within the Adobe Acrobat Chrome extension, enabling UXSS-class behavior that bypasses the browser's same-origin policy. An attacker can exploit this by crafting a malicious URL or compromised web page that, when visited by a victim, causes the extension to disclose session data from cross-origin contexts. Exploitation requires user interaction — the victim must visit a maliciously crafted URL or interact with a compromised page — but no authentication or elevated privileges are required on the attacker's side. The scope is marked as "Changed," indicating the vulnerability's impact extends beyond the vulnerable component itself (Feedly, VulDB).
Successful exploitation results in high confidentiality impact, as an attacker can gain unauthorized access to the victim's session data from cross-origin web contexts, potentially exposing authentication tokens, cookies, or other sensitive information present in the browser session. There is no integrity or availability impact. Because the scope is changed, the vulnerability can affect resources beyond the extension itself, increasing the risk of session hijacking or account takeover on third-party sites (Feedly, EUVD).
Users should update the Adobe Acrobat PDF Extension for Chrome to a version later than 26.5.2.2, which addresses this vulnerability. If an update is not immediately available, users should consider disabling the Adobe Acrobat Chrome extension until a patched version is installed. Additionally, users should avoid visiting suspicious or untrusted URLs and exercise caution with links received via email or messaging platforms (Feedly, Chrome Web Store).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."