CVE-2026-48359
Adobe Experience Manager is vulnerable to an XML External Entity (XXE) flaw that lets a low‑privileged attacker read sensitive files or run code without any user interaction. The vulnerability changes the scope of the affected system and can be triggered over the network.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Adobe Experience Manager, including version 6.5 and other unspecified releases. The typical user is an organization that runs Adobe Experience Manager for web content management.
Real-world impact
An attacker can read confidential files on the server, potentially gain elevated access or take control of the victim’s account or session, leading to data loss or system compromise.
Why this severity
The CVSS score of 9.6 reflects a network‑based attack that requires only low privileges, no user interaction, and provides high confidentiality and integrity impact while changing the system’s scope.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 15, 2026 · 19d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 17, 2026 · 16d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- helpx.adobe.com/security/products/experienc…vendor advisory