Improper XML Handling in Adobe Experience Manager
CVE-2026-48359

9.6CRITICAL

What is CVE-2026-48359?

Adobe Experience Manager is vulnerable to an Improper Restriction of XML External Entity Reference (XXE) issue, which may allow a low-privileged attacker to exploit this flaw. By manipulating XML input, attackers can potentially access sensitive files, thus gaining elevated privileges or controlling the victim's session. This vulnerability can be exploited without any user interaction, increasing the risk of malicious activities and unauthorized access.

Affected Version(s)

Adobe Experience Manager 6.5 0 <= 6.5.25

Adobe Experience Manager 6.5 0 <= 6.5.25

Adobe Experience Manager 6.5 LTS 0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.