
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-46889 is an Improper Access Control vulnerability in Adobe Experience Manager (AEM) that allows a low-privileged attacker to escalate privileges and gain limited unauthorized elevated access without any user interaction. It affects AEM versions 6.5.22 and earlier, as well as AEM Cloud Service versions prior to 2025.5.0. The vulnerability was published on June 10, 2025, with a patch made available shortly after. It carries a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory).
The vulnerability is classified under CWE-284 (Improper Access Control), indicating that the application fails to properly restrict access to resources or functionality based on the authenticated user's privilege level. An attacker with low-level network access can exploit this flaw to bypass security controls and gain elevated permissions within the AEM environment. No user interaction is required, and the attack complexity is low, making it straightforward to exploit once an attacker has a valid low-privileged account. No public technical write-ups or proof-of-concept code have been identified at this time (Adobe Advisory).
Successful exploitation allows a low-privileged attacker to bypass access controls and gain limited unauthorized elevated access within the Adobe Experience Manager environment, affecting both confidentiality and integrity (low impact each), with no availability impact. This could expose sensitive content, configurations, or administrative functionality that should be restricted to higher-privileged users. The scope is limited to the affected AEM instance, but unauthorized access to elevated functions could facilitate further reconnaissance or data exposure within the platform (Adobe Advisory).
There is currently no public proof-of-concept exploit code and no evidence of in-the-wild exploitation for CVE-2025-46889. The EPSS score is approximately 0.033%, reflecting a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Adobe Advisory).
Adobe has released patched versions to address this vulnerability. Affected organizations should upgrade to Adobe Experience Manager 6.5.23.0 or later for on-premises deployments, or ensure their AEM Cloud Service is updated to version 2025.5.0 or later. In addition to patching, administrators should review and restrict user access controls, apply the principle of least privilege, and monitor for unusual privilege escalation activity within AEM (Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."