CRITICAL

CVE-2025-54253

Adobe Experience Manager Forms 2025-08-05 CVSS v3.1
CVSS
10
KEV

Description

Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

Summary dbcve.org

Adobe Experience Manager versions 6.5.23 and earlier contain a misconfiguration that allows attackers to bypass security mechanisms and achieve arbitrary code execution. The vulnerability requires no user interaction and involves a scope change, indicating the attack can impact components beyond the vulnerable AEM instance.

Mitigation

Update Adobe Experience Manager to a version newer than 6.5.23 to remediate this vulnerability. Review AEM security configurations and audit for any unauthorized changes.

Proof of Concept

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

87.99%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE