Server-Side Request Forgery Vulnerability in Adobe Experience Manager
CVE-2026-48259

9.6CRITICAL

What is CVE-2026-48259?

Adobe Experience Manager is susceptible to a Server-Side Request Forgery (SSRF) vulnerability that could allow an attacker with low privileges to send unauthorized server-side requests. Exploitation of this vulnerability can lead to arbitrary code execution within the context of the current user, potentially granting the attacker enhanced access to the victim's account or session without requiring any user interaction. This change in scope heightens the risk associated with improper handling of server requests.

Affected Version(s)

Adobe Experience Manager 6.5 0 <= 6.5.25

Adobe Experience Manager 6.5 0 <= 6.5.25

Adobe Experience Manager 6.5 LTS 0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.