Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and customer experiences, is affected by a security flaw that allows for unauthorized web redirects. An attacker can trick users into clicking a specially crafted link that appears to be legitimate but instead sends them to a malicious website. This could be used in phishing campaigns to steal user credentials or sensitive account information.
Technical details
An Open Redirect vulnerability (CWE-601) exists in Adobe Experience Manager due to improper validation of user-supplied input used in HTTP redirects. A remote, unauthenticated attacker can exploit this by crafting a URL that points to a legitimate Adobe Experience Manager domain but includes a malicious destination in a redirect parameter. If a user clicks the link, the application will automatically redirect them to the external, attacker-controlled site. This flaw is primarily used to facilitate phishing attacks or to bypass security filters to achieve account takeover. The vulnerability affects versions 6.5.24, LTS SP1, 2026.04 and earlier.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory