Adobe Experience Manager Auth Bypass in Critical Function
CVE-2026-48252 Published on July 14, 2026
Adobe Experience Manager | Missing Authentication for Critical Function (CWE-306)
Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
Vulnerability Analysis
CVE-2026-48252 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-48252
Want to know whenever a new CVE is published for Adobe Experience Manager? stack.watch will email you.
Affected Versions
Adobe Experience Manager as a Cloud Service:- Before and including 2026.5.0 is affected.
- Version 2026.6.0 is unaffected.
- Before and including SP2 is affected.
- Version SP2 - Hotfix for NPR-43972 is unaffected.
- Before and including 6.5.25 is affected.
- Version 6.5.25 - Hotfix for NPR-43971 is unaffected.