CVE-2026-48289: Adobe Experience Manager
Low severity, CVSS 3.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Affected products
- Adobe Experience Manager: before 6.5.25.0 (fixed in 6.5.25.0); before 2026.5.0 (fixed in 2026.5.0); version 6.5 only
Published 2026-06-09. Last modified 2026-08-28.