Impact
An improper input validation flaw exists in Adobe Experience Manager that allows a low‑privileged attacker to bypass built‑in security controls and obtain write access that should be protected. This vulnerability is specifically tied to CWE‑20 and requires a user to visit a maliciously crafted URL or interact with a compromised web page to trigger the flaw; no remote code execution or privilege escalation beyond the web application boundary is possible.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and all earlier builds are affected. Updated releases released after 2026.04 contain the fix and are not considered vulnerable.
Risk and Exploitability
The CVSS score of 3.5 classifies this issue as low severity, and the EPSS metric is currently unavailable, indicating a limited but unknown exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires user interaction with a malicious URL, the attack surface is restricted to individuals who can lure a target into visiting the malicious site, which reduces the likelihood of widespread abuse.
OpenCVE Enrichment