CVE-2026-47991

Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could lead to account takeover. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Adobe Experience Manager versiones 6.5.24, LTS SP1, 2026.04 y anteriores están afectadas por una vulnerabilidad de redirección incorrecta (redirección abierta) que podría llevar a la toma de control de la cuenta. Un atacante podría construir una URL maliciosa que redirige a una víctima a un sitio controlado por el atacante. La explotación de este problema requiere interacción del usuario en el sentido de que una víctima debe hacer clic en un enlace malicioso.

10 Jun 2026, 14:56

Type Values Removed Values Added
First Time Adobe
Adobe experience Manager
CPE cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
References () https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html - () https://helpx.adobe.com/security/products/experience-manager/apsb26-56.html - Vendor Advisory

09 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 17:17

Updated : 2026-07-23 08:10


NVD link : CVE-2026-47991

Mitre link : CVE-2026-47991

CVE.ORG link : CVE-2026-47991


JSON object : View

Products Affected

adobe

  • experience_manager
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')