Impact
Adobe Experience Manager is vulnerable to an improper redirect that allows an attacker to construct a malicious URL, which when clicked by a user causes the browser to navigate to an attacker‑controlled site. The vulnerability is classified as an Open Redirect (CWE‑601). It can be used to direct users to sites that might host phishing content or other malicious payloads, but it requires explicit user interaction by clicking the crafted link.
Affected Systems
This issue affects Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and all earlier releases. Any installation running one of these versions is susceptible until an updated release or patch is applied.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score of < 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Exploitation requires a victim to click a malicious link, so the risk is limited to users who encounter such links, while the scope change indicates the potential for broader impact if the redirect bypass is successfully leveraged.
OpenCVE Enrichment