Adobe disclosed an Incorrect Authorization vulnerability in Adobe Experience Manager that, per the vendor advisory, could result in arbitrary code execution and carries a CVSS 3.1 base score of 9.9.
What Is It
CVE-2026-19232 is an Incorrect Authorization flaw (CWE-863) in Adobe Experience Manager. According to Adobe's advisory (APSB26-98), the vulnerability "could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session." The CVSS metrics indicate that an attacker holding only low privileges could reach this outcome, and that exploitation does not require user interaction.
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, only low privileges needed, no user interaction, and a changed scope, with high impact to confidentiality, integrity, and availability. The record was published 2026-09-08 and currently sits in "Awaiting Analysis" status at NVD.
Why It Matters
The 9.9 score is driven by the combination of low privilege requirement and changed scope: an attacker who already holds a minimal AEM account could break out of that authorization boundary and affect resources beyond the vulnerable component. AEM is a content management platform typically deployed as internet-facing infrastructure, which aligns with the NETWORK attack vector. No user interaction is required, removing the need for any social engineering step.
CVE-2026-19232 does not appear in the CISA Known Exploited Vulnerabilities catalog as of this writing, so active exploitation is not confirmed at this time.
What's Vulnerable
Per Adobe's affected-product table in APSB26-98:
- Adobe Experience Manager as a Cloud Service: all versions up to and including 2026.7.0 are affected; 2026.8.0 is unaffected.
- Adobe Experience Manager 6.5 LTS: versions up to and including SP2 are affected; SP3 is unaffected.
- Adobe Experience Manager 6.5: versions up to and including 6.5.24 are affected; 6.5.25 is unaffected.
Patch Status
Fixed releases are available. Cloud Service users should be on 2026.8.0 or later. On-premises 6.5 LTS deployments should move to SP3, and AEM 6.5 deployments to 6.5.25. Adobe's security bulletin APSB26-98 is the authoritative reference for the fix. Because the CVE is not listed in the CISA KEV catalog, no BOD 22-01 remediation deadline applies to federal civilian agencies; organizations should patch on their normal critical-severity timeline.
Sources
- Adobe Security Bulletin APSB26-98; https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html
- NVD, CVE-2026-19232, https://nvd.nist.gov/vuln/detail/CVE-2026-19232
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog