---
id: CVE-2026-48310
title: >-
  Adobe Experience Manager is affected by an Improper Limitation of a Pathname
  to a Restricted Directory ('Path Traversal') vulnerability that could lead to
  arbitrary file system read
summary: >-
  Adobe Experience Manager is affected by an Improper Limitation of a Pathname
  to a Restricted Directory ('Path Traversal') vulnerability that could lead to
  arbitrary file system read. An attacker could exploit this vulnerability to
  access…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: adobe
product: experience_manager
affected:
  - experience_manager <= 6.5.25.0
  - experience_manager <= 2020.5.0
  - experience_manager = 6.5
published: '2026-07-14'
updated: '2026-07-17'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48310'
references:
  - url: >-
      https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.01047
epssPercentile: 0.62659
ingestedAt: '2026-07-18T13:23:33.965Z'
---

## Overview

Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

## Affected

- `experience_manager <= 6.5.25.0`
- `experience_manager <= 2020.5.0`
- `experience_manager = 6.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
