Description
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Experience Manager is vulnerable to a Server‑Side Request Forgery (SSRF) flaw that allows an attacker to instruct the application to send requests to arbitrary internal or external servers. The flaw can result in arbitrary code execution in the context of the current user; a low‑privileged attacker can exploit it to gain elevated privileges or take over the victim’s account. The vulnerability is network‑based, does not require user interaction, and changes the scope so that exploitation may affect the entire site.

Affected Systems

Adobe publishes the vulnerability against all versions of Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Cloud Service edition. All instances of these products are susceptible until a patch is applied, with no specific sub‑versions singled out.

Risk and Exploitability

The CVSS score of 9.6 indicates critical severity, while the EPSS score of under 1% suggests a low current probability of exploitation. The flaw is not listed in CISA KEV. Based on the SSRF nature, the attack path likely involves an attacker crafting a request that forces the AEM server to send a probe to an internal endpoint; this is inferred from the description that the attacker can issue unauthorized server‑side requests. Because the attacker only needs access to the network path used by AEM and no user interaction, the risk for organizations with exposed AEM instances remains high.

Generated by OpenCVE AI on July 31, 2026 at 05:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Experience Manager security patch that addresses the Server‑Side Request Forgery flaw.
  • If patching cannot occur immediately, temporarily restrict or disable outbound requests from the AEM instance to limit malicious traffic.
  • Implement firewall or proxy rules to block AEM‑initiated requests to sensitive internal endpoints, reducing the potential attack surface.

Generated by OpenCVE AI on July 31, 2026 at 05:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T19:38:48.192Z

Reserved: 2026-05-21T15:28:38.131Z

Link: CVE-2026-48259

cve-icon Vulnrichment

Updated: 2026-07-15T10:31:03.824Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)