---
id: CVE-2026-19232
title: >-
  Adobe Experience Manager is affected by an Incorrect Authorization
  vulnerability that could result in arbitrary code execution in the context of
  the current user, potentially gaining elevated access or control over the
  victim's account o…
summary: >-
  Adobe Experience Manager is affected by an Incorrect Authorization
  vulnerability that could result in arbitrary code execution in the context of
  the current user, potentially gaining elevated access or control over the
  victim's account o…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: adobe
product: experience_manager
affected:
  - experience_manager < 6.5
  - experience_manager < 6.5.25.0
  - experience_manager < 2026.8.0
  - experience_manager = 6.5
patched:
  - experience_manager 2026.8.0
published: '2026-09-08'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T14:02:47.597'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19232'
references:
  - url: >-
      https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
epss: 0.00573
epssPercentile: 0.46128
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T15:59:35.462778Z'
ingestedAt: '2026-09-08T20:10:03.217Z'
---

## Overview

Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

## Affected

- `experience_manager < 6.5`
- `experience_manager < 6.5.25.0`
- `experience_manager < 2026.8.0`
- `experience_manager = 6.5`

## Remediation

Upgrade past the affected range:

- `experience_manager 2026.8.0`
