CVE-2026-48259
published 2026-07-14CVE-2026-48259: Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the…
PriorityP268critical9.6CVSS 3.1
AVNACLPRLUINSCCHIHAN
EPSS
0.41%
33.1th percentile
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_experience_manager_6.5 | <= 6.5.25 | — |
| adobe | adobe_experience_manager_6.5_lts | <= SP2 | — |
| adobe | adobe_experience_manager_as_a_cloud_service | <= 2026.5.0 | — |
| adobe | experience_manager | <= 6.5.25.0 | — |
| adobe | experience_manager | <= 2020.5.0 | — |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Experience Manager server-side request forgery (Nessus ID 327021)
vuldb·2026-07-16·CVSS 9.6
CVE-2026-48259 [CRITICAL] Adobe Experience Manager server-side request forgery (Nessus ID 327021)
A vulnerability marked as critical has been reported in Adobe Experience Manager. Impacted is an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-48259. The attack is possible to be carried out remotely. No exploit exists.
GHSA
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user.
ghsa_unreviewed·2026-07-14
CVE-2026-48259 [CRITICAL] CWE-918 Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user.
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
No detection rules found.
No public exploits indexed.
2026-07-14
Published