Description
Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Experience Manager is vulnerable to an improper limitation of a pathname to a restricted directory, a path traversal flaw that allows arbitrary file system read. It permits an attacker to access sensitive files and directories outside the intended scope. The vulnerability can be exploited remotely without any user interaction and changes the security scope of the affected services. The flaw is identified as CWE‑22.

Affected Systems

Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are impacted.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via crafted HTTP requests that exploit the path handling logic to traverse beyond the intended directory, bypassing directory restrictions.

Generated by OpenCVE AI on July 31, 2026 at 05:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Experience Manager 6.5, 6.5 LTS, or Cloud Service patch released by Adobe to remediate the path traversal flaw; refer to the advisory at https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html for update details.
  • Ensure that all file‑path inputs used by the application are strictly validated and normalized, rejecting or sanitizing any path components that attempt to traverse outside the intended base directory.
  • Deploy a web application firewall or HTTP request filter that blocks URL paths containing suspicious traversal patterns (e.g., ".." or percent‑encoded equivalents) and monitor logs for attempted read operations.

Generated by OpenCVE AI on July 31, 2026 at 05:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Experience Manager | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-16T14:44:17.004Z

Reserved: 2026-05-21T15:28:38.136Z

Link: CVE-2026-48310

cve-icon Vulnrichment

Updated: 2026-07-16T14:44:06.983Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')