Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security bypass vulnerability. An attacker with low-level access could trick a legitimate user into visiting a malicious link to gain unauthorized ability to modify content on the site. This could lead to unauthorized changes to website information or digital assets, potentially impacting brand integrity.
Technical details
An Improper Input Validation vulnerability (CWE-20) exists in Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw allows a security feature bypass due to insufficient validation of user-supplied input. To exploit the vulnerability, a low-privileged attacker must entice a victim to visit a maliciously crafted URL or interact with a compromised web page (User Interaction required). Successful exploitation enables the attacker to gain unauthorized write access to the application. The vulnerability is reachable over the network and has been assigned a CVSS score of 3.5.
Affected products
- Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier
Timeline
- 2026-06-09: disclosed: Initial publication of the advisory by Adobe and NVD.