Improper XML Handling in Adobe Experience Manager
CVE-2026-48359
9.6CRITICAL
Key Information:
- Vendor
Adobe
- Status
- Vendor
- CVE Published:
- 14 July 2026
What is CVE-2026-48359?
Adobe Experience Manager is vulnerable to an Improper Restriction of XML External Entity Reference (XXE) issue, which may allow a low-privileged attacker to exploit this flaw. By manipulating XML input, attackers can potentially access sensitive files, thus gaining elevated privileges or controlling the victim's session. This vulnerability can be exploited without any user interaction, increasing the risk of malicious activities and unauthorized access.
Affected Version(s)
Adobe Experience Manager 6.5 0 <= 6.5.25
Adobe Experience Manager 6.5 0 <= 6.5.25
Adobe Experience Manager 6.5 LTS 0