An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAdobe Experience Manager
APPAdobe≤ 6.2.1.206.3.0.0 – 6.3.3.86.4.0.0 – 6.4.8.16.5.0.0 – 6.5.5.0Adobe Experience Manager Forms
APPAdobe6.4.8.16.5.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2025-54253CRITICAL10.0⚠ KEVPL ✓same product
RCE przez błędną konfigurację w Adobe Experience Manager Forms
CVE-2026-48259CRITICAL9.6PL ✓same product
Adobe Experience Manager — SSRF umożliwiający zdalne wykonanie kodu
CVE-2026-48359CRITICAL9.6PL ✓same product
Adobe Experience Manager — XXE umożliwiające RCE i odczyt plików
CVE-2026-34691CRITICAL9.3PL ✓same product
Stored XSS w Adobe Experience Manager Forms JEE – krytyczna podatność
CVE-2025-64537CRITICAL9.3PL ✓same product
DOM-based XSS w Adobe Experience Manager umożliwiający RCE