CVE-2026-19232

9.9

Adobe · Experience Manager

Adobe Experience Manager contains an incorrect authorization vulnerability allowing low privileged users to achieve arbitrary code execution.

Executive summary

A critical authorization vulnerability in Adobe Experience Manager enables low privileged attackers to execute arbitrary code, creating a high risk of full system compromise.

Vulnerability

This flaw stems from improper authorization checks (CWE-863) that allow a low privileged, authenticated attacker to bypass security constraints and execute arbitrary code. The vulnerability does not require user interaction and carries a scope change, allowing the attacker to impact components outside the original security context.

Business impact

The CVSS score of 9.9 reflects the extreme severity of this vulnerability, as it provides a pathway for attackers to gain elevated control over critical enterprise content management infrastructure. Successful exploitation could lead to total system compromise, unauthorized data exfiltration, and significant reputational damage to the organization.

Remediation

Immediate Action: Update Adobe Experience Manager as a Cloud Service to version 2026.8.0 or later, Adobe Experience Manager 6.5 LTS to SP3 or later, or Adobe Experience Manager 6.5 to version 6.5.25 or later as specified in APSB26-98.

Proactive Monitoring: Inspect server logs for unauthorized administrative actions or unusual process execution patterns originating from low privileged service accounts.

Compensating Controls: Implement strict network segmentation and egress filtering to limit the potential reach of an attacker in the event of successful code execution.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical CVSS severity score of 9.9, this vulnerability represents an immediate threat to the confidentiality, integrity, and availability of the affected Adobe environments. Organizations must prioritize the deployment of the vendor-supplied patches to eliminate the authorization bypass vector and secure the application against potential exploitation.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources