CVE-2026-19232
largeIncorrect Authorization in Adobe Experience Manager Enables Arbitrary Code Execution
CVE-2026-19232 is an incorrect authorization flaw (CWE-863) in Adobe Experience Manager (AEM) in which permission checks are not properly enforced, letting requests reach functionality a low-privileged user should not be able to invoke. It is triggered over the network by an authenticated low-privileged attacker, requires no user interaction, and carries a changed scope (S:C), meaning the impact can extend beyond the vulnerable component into the broader AEM instance. A successful attacker gains arbitrary code execution in the context of the current user and can potentially obtain elevated access or control over the victim's account or session, with confidentiality, integrity, and availability impacts all rated high (CVSS 3.1: 9.9 critical). Any organization running an affected version of AEM is exposed; the available data does not specify affected version ranges, so defenders should consult Adobe's security bulletin for exact versions. There is no evidence of active exploitation so far: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.6% probability of exploitation in the next 30 days (45th percentile).
What to do: Check Adobe's security bulletin (CNA: [email protected]) for the affected AEM version ranges and apply the patched release as soon as it is identified, treating this as a critical-priority patch given the 9.9 CVSS score. Until patched, restrict network access to AEM author and publish instances, review and tighten permissions granted to low-privileged users, and monitor logs for anomalous session activity or account-takeover indicators. No public PoC or known in-the-wild exploitation exists today, but the severity and changed scope warrant prompt remediation.
| Adobe Experience Manager | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
- Vendors
- adobe
- Products
- experience manager
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.