Executive brief
Adobe Experience Manager, a platform used by organizations to manage digital content and customer experiences, is affected by a critical security vulnerability. An attacker with low-level access can exploit this flaw to read sensitive internal files or potentially take control of the system. This could lead to the theft of confidential data or a complete compromise of the content management platform without requiring any interaction from legitimate users.
Technical details
Adobe Experience Manager is vulnerable to an XML External Entity (XXE) injection (CWE-611). The vulnerability exists due to improper restriction of XML external entity references during the processing of XML data. A remote attacker with low-privileged credentials can exploit this by sending a specially crafted XML payload to the server. Successful exploitation allows the attacker to read arbitrary files from the server's filesystem, perform server-side request forgery (SSRF), and potentially achieve arbitrary code execution. The vulnerability is particularly severe as it involves a scope change (S:C), indicating the impact can extend beyond the immediate software component. Patches are available in versions 2026.6.0, 6.5 LTS SP2, and 6.5.25.
Affected products
- Adobe Experience Manager as a Cloud Service <= 2026.5.0
- Adobe Experience Manager 6.5 LTS <= SP1
- Adobe Experience Manager 6.5 <= 6.5.24
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory