ZeroHour

CVE-2026-19232

large

Incorrect Authorization in Adobe Experience Manager Enables Arbitrary Code Execution

CVSS 3.1
9.9 critical
EPSS
<1%p45
Published
()
Modified
AI analysis

CVE-2026-19232 is an incorrect authorization flaw (CWE-863) in Adobe Experience Manager (AEM) in which permission checks are not properly enforced, letting requests reach functionality a low-privileged user should not be able to invoke. It is triggered over the network by an authenticated low-privileged attacker, requires no user interaction, and carries a changed scope (S:C), meaning the impact can extend beyond the vulnerable component into the broader AEM instance. A successful attacker gains arbitrary code execution in the context of the current user and can potentially obtain elevated access or control over the victim's account or session, with confidentiality, integrity, and availability impacts all rated high (CVSS 3.1: 9.9 critical). Any organization running an affected version of AEM is exposed; the available data does not specify affected version ranges, so defenders should consult Adobe's security bulletin for exact versions. There is no evidence of active exploitation so far: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.6% probability of exploitation in the next 30 days (45th percentile).

What to do: Check Adobe's security bulletin (CNA: [email protected]) for the affected AEM version ranges and apply the patched release as soon as it is identified, treating this as a critical-priority patch given the 9.9 CVSS score. Until patched, restrict network access to AEM author and publish instances, review and tighten permissions granted to low-privileged users, and monitor logs for anomalous session activity or account-takeover indicators. No public PoC or known in-the-wild exploitation exists today, but the severity and changed scope warrant prompt remediation.

Affected
Adobe Experience Manager
Estimated exposure
large≈ tens of thousands of deployed/internet-exposed AEM instances (estimated) — AEM is an enterprise-only CMS/DAM platform whose deployments are concentrated in large organizations, and public internet scans have historically indexed on the order of tens of thousands of exposed AEM instances; this order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
experience manager
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.