Adobe Experience Manager Auth Bypass in Critical Function
CVE-2026-48252 Published on July 14, 2026

Adobe Experience Manager | Missing Authentication for Critical Function (CWE-306)
Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-48252 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-48252

Want to know whenever a new CVE is published for Adobe Experience Manager? stack.watch will email you.

 

Affected Versions

Adobe Experience Manager as a Cloud Service: Adobe Experience Manager 6.5 LTS: Adobe Experience Manager 6.5: