CVE-2026-48294
Adobe Acrobat Classic vulnerability analysis and mitigation

Overview

CVE-2026-48294 is a Universal Cross-Site Scripting (UXSS)-class cross-origin data disclosure vulnerability in the Adobe Acrobat PDF Extension for Chrome. It affects versions 26.5.2.2 and earlier of the browser extension, allowing attackers to access sensitive session data across origins. The vulnerability was published on June 17, 2026, and assigned a CVSS v3.1 base score of 7.4 (High) (Feedly, EUVD).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting) and stems from improper origin validation within the Adobe Acrobat Chrome extension, enabling UXSS-class behavior that bypasses the browser's same-origin policy. An attacker can exploit this by crafting a malicious URL or compromised web page that, when visited by a victim, causes the extension to disclose session data from cross-origin contexts. Exploitation requires user interaction — the victim must visit a maliciously crafted URL or interact with a compromised page — but no authentication or elevated privileges are required on the attacker's side. The scope is marked as "Changed," indicating the vulnerability's impact extends beyond the vulnerable component itself (Feedly, VulDB).

Impact

Successful exploitation results in high confidentiality impact, as an attacker can gain unauthorized access to the victim's session data from cross-origin web contexts, potentially exposing authentication tokens, cookies, or other sensitive information present in the browser session. There is no integrity or availability impact. Because the scope is changed, the vulnerability can affect resources beyond the extension itself, increasing the risk of session hijacking or account takeover on third-party sites (Feedly, EUVD).

Exploitation steps

  1. Reconnaissance: Identify targets who have the Adobe Acrobat PDF Extension for Chrome (version 26.5.2.2 or earlier) installed, which can be inferred through browser fingerprinting or social engineering.
  2. Craft malicious payload: Develop a maliciously crafted URL or web page that exploits the improper origin validation in the extension to inject or execute cross-origin script content.
  3. Deliver the payload: Lure the victim into visiting the malicious URL or compromised web page via phishing, malvertising, or a compromised legitimate site.
  4. Trigger UXSS: When the victim's browser processes the page with the vulnerable extension active, the UXSS payload executes in the context of a cross-origin page, bypassing the same-origin policy.
  5. Exfiltrate session data: The injected script reads sensitive session data (e.g., cookies, tokens, page content) from the cross-origin context and transmits it to an attacker-controlled server (Feedly, EUVD).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from the browser to unknown or attacker-controlled domains shortly after visiting an unfamiliar URL; exfiltration of session tokens or cookies via GET/POST requests to external endpoints.
  • Logs: Browser or proxy logs showing navigation to suspicious URLs followed by cross-origin resource requests initiated by the Adobe Acrobat extension; unusual referrer chains in web server logs.
  • Browser Behavior: The Adobe Acrobat extension making requests to origins unrelated to the current page context; unexpected script execution attributed to the extension in browser developer tools.

Mitigation and workarounds

Users should update the Adobe Acrobat PDF Extension for Chrome to a version later than 26.5.2.2, which addresses this vulnerability. If an update is not immediately available, users should consider disabling the Adobe Acrobat Chrome extension until a patched version is installed. Additionally, users should avoid visiting suspicious or untrusted URLs and exercise caution with links received via email or messaging platforms (Feedly, Chrome Web Store).

Additional resources


SourceThis report was generated using AI

Related Adobe Acrobat Classic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-9695HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2026-47965HIGH7.8
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat
NoYesJun 12, 2026
CVE-2026-48294HIGH7.4
  • Adobe Acrobat Classic logoAdobe Acrobat Classic
  • cpe:2.3:a:adobe:acrobat
NoNoJun 17, 2026
CVE-2020-9713MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026
CVE-2020-9711MEDIUM5.5
  • Adobe Acrobat Reader Continuous logoAdobe Acrobat Reader Continuous
  • cpe:2.3:a:adobe:acrobat_dc
NoYesJun 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management