Impact
The vulnerability stems from improper input validation that permits a low‑privileged attacker to bypass security measures and gain write rights to application content. The flaw allows crafted data to circumvent standard safeguards, enabling an attacker to modify or inject data without having system‑wide control.
Affected Systems
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and all earlier releases are affected; the product is listed by the CNA as Adobe Experience Manager.
Risk and Exploitability
The CVSS score of 3.5 classifies the problem as low severity and the EPSS score is not available, with no listing in the CISA KEV catalogue. Exploitation requires user interaction, such as opening a malicious URL or interacting with a compromised web page, limiting the attack likelihood to environments where users encounter such content.
OpenCVE Enrichment