Junglewise Threat Intelligence

CVE-2026-48310: Adobe Experience Manager path traversal in file system access

CVE-2026-48310 · Severity: high · CVSS 8.6 · Published 2026-07-14

Technologies: Adobe Experience Manager as a Cloud Service. Vendors: Adobe.

Executive brief

Adobe Experience Manager, a platform used for managing digital content and assets, is affected by a security flaw that allows unauthorized access to the underlying server's file system. An attacker could exploit this to read sensitive configuration files or internal data without needing any user interaction or login credentials. This could lead to the exposure of confidential business information or credentials used to further compromise the corporate network.

Technical details

A path traversal vulnerability (CWE-22) exists in Adobe Experience Manager due to improper limitation of pathnames to restricted directories. An unauthenticated remote attacker can exploit this by sending specially crafted requests to the server, allowing them to bypass access controls and read sensitive files outside of the web root. The vulnerability has a CVSS 3.1 score of 8.6, notably featuring a 'Changed' scope (S:C), indicating that the impact extends beyond the application itself to the underlying host system. Adobe has released updates for Cloud Service, 6.5 LTS, and 6.5 versions to address this issue.

Affected products

  • Adobe Experience Manager as a Cloud Service <= 2026.5.0
  • Adobe Experience Manager 6.5 LTS <= SP1
  • Adobe Experience Manager 6.5 <= 6.5.24

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References