CVE-2026-48288
Estado: AnalizadaBaja (3.5)—
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Puntuación base: 3.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.54%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-48288",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-48288",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-10T13:54:28.650518Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.5,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "Adobe",
"product": "Adobe Experience Manager as a Cloud Service",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2026.4.0"
},
{
"status": "unaffected",
"version": "2026.5.0",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Adobe",
"product": "Adobe Experience Manager 6.5 LTS",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "SP1"
},
{
"status": "unaffected",
"version": "SP2",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Adobe",
"product": "Adobe Experience Manager 6.5",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "6.5.24"
},
{
"status": "unaffected",
"version": "6.5.25",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-09T17:17:43.623",
"references": [
{
"url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html",
"tags": [
"Vendor Advisory"
],
"source": "psirt@adobe.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page."
},
{
"lang": "es",
"value": "Las versiones 6.5.24, LTS SP1, 2026.04 y anteriores de Adobe Experience Manager están afectadas por una vulnerabilidad de validación de entrada incorrecta que podría resultar en una omisión de característica de seguridad. Un atacante con pocos privilegios podría aprovechar esta vulnerabilidad para eludir medidas de seguridad y obtener acceso de escritura no autorizado. La explotación de este problema requiere interacción del usuario, en el sentido de que una víctima debe visitar una URL creada con fines maliciosos o interactuar con una página web comprometida."
}
],
"lastModified": "2026-08-28T00:17:44.280",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97A52D44-B2A5-4572-AA3C-03B707802048",
"versionEndExcluding": "6.5.25.0"
},
{
"criteria": "cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE90F248-EA8C-4801-8CA6-4B3CC2A7F160",
"versionEndExcluding": "2026.5.0"
},
{
"criteria": "cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "852C2582-859F-40DB-96CF-E1274CEECC1F"
},
{
"criteria": "cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00DDCBAD-1FEF-487F-97BB-481DC02F493A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@adobe.com"
}