Description
Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-08
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an incorrect authorization flaw (CWE‑863) that allows a low‑privileged attacker to execute arbitrary code within the context of the current user. This could let the attacker gain elevated access or control over the victim’s account or session. The flaw does not require any user interaction and changes the system scope.

Affected Systems

Affected products are Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service.

Risk and Exploitability

The CVSS score is 9.9, indicating critical severity. The EPSS score is unavailable, but the lack of user interaction and scope‑changing nature suggest the vulnerability could be exploited whenever an authenticated user is present. The flaw is not listed in the CISA KEV catalog. Likely the attack vector involves a malicious request to an authenticated endpoint that leverages the incorrect authorization to elevate privileges. Because the flaw is high‑severity and the potential impact is arbitrary code execution, the risk to exposed systems is high.

Generated by OpenCVE AI on September 9, 2026 at 12:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe patch or upgrade detailed in APSB26‑98 to Adobe Experience Manager 6.5, 6.5 LTS, or the Cloud Service.
  • If a patch is not yet available, restrict or block access to the vulnerable managed components and enforce least‑privilege access controls on Experience Manager instances.
  • Enable detailed logging and monitoring of administrative activity to detect any abnormal code execution or privilege escalation events.

Generated by OpenCVE AI on September 9, 2026 at 12:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe experience Manager
CPEs cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*
Vendors & Products Adobe
Adobe experience Manager

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Experience Manager | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Experience Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T03:56:56.831Z

Reserved: 2026-08-07T11:08:20.789Z

Link: CVE-2026-19232

cve-icon Vulnrichment

Updated: 2026-09-09T15:59:53.335Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:17:28.940

Modified: 2026-09-11T14:02:47.597

Link: CVE-2026-19232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T12:30:09Z

Weaknesses