Junglewise Threat Intelligence

CVE-2026-48259: Adobe Experience Manager SSRF leading to code execution

CVE-2026-48259 · Severity: critical · CVSS 9.6 · Published 2026-07-14

Technologies: Adobe Experience Manager as a Cloud Service. Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used for managing digital content and assets, is affected by a critical security vulnerability. An attacker with low-level access can force the server to make unauthorized requests, which could lead to the attacker taking full control of the system or accessing sensitive user sessions. This issue is particularly serious because it allows an attacker to bypass security boundaries and execute malicious code without any interaction from a legitimate user.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Adobe Experience Manager. The flaw allows a low-privileged authenticated attacker to send unauthorized network requests from the server's perspective. Due to a change in scope (CVSS S:C), this SSRF can be leveraged to achieve arbitrary code execution in the context of the current user. The attack is reachable over the network and does not require user interaction. Adobe has released patches for AEM Cloud Service (2026.6.0), AEM 6.5 LTS (SP2 Hotfix), and AEM 6.5 (6.5.25 Hotfix) to address this issue.

Affected products

  • Adobe Experience Manager as a Cloud Service <= 2026.5.0
  • Adobe Experience Manager 6.5 LTS <= SP1
  • Adobe Experience Manager 6.5 <= 6.5.24

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats