CVE-2024-26119: Adobe Experience Manager

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application. Exploitation of this issue does not require user interaction.

Affected products

  • Adobe Experience Manager: before 6.5.20.0 (fixed in 6.5.20.0); before 2024.3.0 (fixed in 2024.3.0)

Published 2024-03-18. Last modified 2026-06-17.