Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-48310

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
Версия до 6.5.25.0 (включая)
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
Версия до 2020.5.0 (включая)
cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
cpe:2.3:a:adobe:experience_manager:6.5:sp2:*:*:lts:*:*:*

EPSS

Процентиль: 40%
0.00506
Низкий

8.6 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.6
github
17 дней назад

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS3: 8.6
fstec
18 дней назад

Уязвимость системы управления контентом и медиа-данными Adobe Experience Manager, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю обойти существующие механизмы безопасности

EPSS

Процентиль: 40%
0.00506
Низкий

8.6 High

CVSS3

Дефекты

CWE-22