CVE-2026-75726 PUBLISHED

Adobe Experience Manager | Improper Input Validation (CWE-20)

Assigner: adobe
Reserved: 18.08.2026 Published: 08.09.2026 Updated: 08.09.2026

Adobe Experience Manager is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS Score: 3.5

Product Status

Vendor Adobe
Product Adobe Experience Manager as a Cloud Service
Versions Default: unaffected
  • affected from 0 to 2026.7.0 (incl.)
  • Version 2026.8.0 is unaffected
Vendor Adobe
Product Adobe Experience Manager 6.5 LTS
Versions Default: unaffected
  • affected from 0 to SP2 (incl.)
  • Version SP3 is unaffected
Vendor Adobe
Product Adobe Experience Manager 6.5
Versions Default: unaffected
  • affected from 0 to 6.5.24 (incl.)
  • Version 6.5.25 is unaffected

References

Problem Types

  • Improper Input Validation (CWE-20) CWE