Description

Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.

Severity (CVSS)

Base score8.6
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Provided byCNA

Weaknesses

  • CWE-306 — Missing Authentication for Critical Function (CWE-306)

Affected products

VendorProductVersions
AdobeAdobe Experience Manager as a Cloud Service0 to <=2026.5.0; 2026.6.0
AdobeAdobe Experience Manager 6.5 LTS0 to <=SP1; SP2 - Hotfix for NPR-43972
AdobeAdobe Experience Manager 6.50 to <=6.5.24; 6.5.25 - Hotfix for NPR-43972

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 15 Jul 2026 07:06 UTC.