Impact
The vulnerability is an incorrect authorization flaw (CWE‑863) that allows a low‑privileged attacker to execute arbitrary code within the context of the current user. This could let the attacker gain elevated access or control over the victim’s account or session. The flaw does not require any user interaction and changes the system scope.
Affected Systems
Affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service.
Risk and Exploitability
The CVSS score is 9.9, indicating critical severity. The EPSS score is unavailable, but the lack of user interaction and scope‑changing nature suggest the vulnerability could be exploited whenever an authenticated user is present. The flaw is not listed in the CISA KEV catalog. Likely the attack vector involves a malicious request to an authenticated endpoint that leverages the incorrect authorization to elevate privileges. Because the flaw is high‑severity and the potential impact is arbitrary code execution, the risk to exposed systems is high.
OpenCVE Enrichment