Junglewise Threat Intelligence

CVE-2026-48289: Adobe Experience Manager security bypass via improper input validation

CVE-2026-48289 · Severity: low · CVSS 3.5 · Published 2026-06-09

Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used by organizations to manage digital content and assets, is affected by a security bypass vulnerability. An attacker with low-level access could trick a legitimate user into clicking a malicious link, allowing the attacker to bypass security controls and gain unauthorized permission to modify content. This could lead to unauthorized changes to website data or corporate digital assets.

Technical details

An improper input validation vulnerability (CWE-20) exists in Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier. The flaw allows a low-privileged remote attacker to bypass security features and achieve unauthorized write access. Exploitation requires a network-based attack vector and user interaction, specifically requiring a victim to visit a maliciously crafted URL or interact with a compromised web page. The vulnerability is rated as low severity with a CVSS score of 3.5, as it impacts integrity but does not directly lead to data confidentiality loss or service unavailability.

Affected products

  • Adobe Experience Manager 6.5.24, LTS SP1, 2026.04 and earlier

Timeline

  • 2026-06-09: advisory: Initial disclosure by Adobe and NVD publication.

References