CVE-2026-48359
published 2026-07-14CVE-2026-48359: Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code…
PriorityP263critical9.6CVSS 3.1
AVNACLPRLUINSCCHIHAN
EPSS
0.53%
41.5th percentile
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_experience_manager_6.5 | <= 6.5.25 | — |
| adobe | adobe_experience_manager_6.5_lts | <= SP2 | — |
| adobe | adobe_experience_manager_as_a_cloud_service | <= 2026.5.0 | — |
| adobe | experience_manager | <= 6.5.25.0 | — |
| adobe | experience_manager | <= 2020.5.0 | — |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
| adobe | experience_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Experience Manager XML External Entity Parser xml external entity reference (Nessus ID 327021)
vuldb·2026-07-16·CVSS 9.6
CVE-2026-48359 [CRITICAL] Adobe Experience Manager XML External Entity Parser xml external entity reference (Nessus ID 327021)
A vulnerability described as critical has been identified in Adobe Experience Manager. The affected element is an unknown function of the component XML External Entity Parser. The manipulation results in xml external entity reference.
This vulnerability was named CVE-2026-48359. The attack may be performed from remote. There is no available exploit.
GHSA
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user.
ghsa_unreviewed·2026-07-14
CVE-2026-48359 [CRITICAL] CWE-611 Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user.
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
No detection rules found.
No public exploits indexed.
2026-07-14
Published