情報 ID
Adobe Experience Manager に関するセキュリティアップデート公開 | APSB26-74
|
|
公開日 |
優先度 |
|---|---|---|
|
APSB26-74 |
2026年7月14日 |
3 |
要約
Adobe Experience Manager (AEM)を対象としたアップデートが公開されました。 このアップデートは、重要と評価されたな脆弱性を解決します。これらの脆弱性が悪用されると、任意のコード実行、セキュリティ機能のバイパス、任意のファイルシステムの読み取り、および権限昇格が発生する可能性があります。
本アップデートによって修正される脆弱性が、広く悪用されているという事例は確認されていません。
対象の製品バージョン
製品 |
バージョン |
プラットフォーム |
|---|---|---|
| Adobe Experience Manager(AEM) |
AEM Cloud Service (CS) リリース 2026.5.0 以前 | すべて |
| Adobe Experience Manager(AEM) | 6.5 LTS Service Pack 2 以前 | すべて |
| Adobe Experience Manager(AEM) | 6.5サービスパック 25 以前 | すべて |
解決方法
アドビは、これらのアップデートを次の優先度評価に分類しており、対象製品をご利用のお客様に最新バージョンへのアップグレードを推奨します。
CVE-2026-48252、CVE-2026-48259、CVE-2026-48263、CVE-2026-48310、および CVE-2026-48355 は、指定された AEMaaCS リリースにのみ影響します。
脆弱性に関する詳細
| Vulnerability Category |
Vulnerability Impact |
Severity |
CVSS base score |
CVSS vector |
CVE Number |
| Server-Side Request Forgery (SSRF) (CWE-918) | Arbitrary code execution | Critical | 9.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N | CVE-2026-48259 |
| Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) | Arbitrary code execution | Critical | 9.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N | CVE-2026-48359 |
| Missing Authentication for Critical Function (CWE-306) | Security feature bypass | Critical | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N | CVE-2026-48252 |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | Arbitrary file system read | Critical | 8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N | CVE-2026-48310 |
| Cross-site Scripting (Stored XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48263 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48253 |
| Cross-site Scripting (Stored XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48355 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48254 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48255 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48257 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48260 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Arbitrary code execution | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48261 |
| Cross-site Scripting (DOM-based XSS) (CWE-79) | Privilege escalation | Important | 5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | CVE-2026-48262 |
If a customer is using Apache httpd in a proxy with a non-default configuration, they may be impacted by CVE-2023-25690 - please read more here: https://httpd.apache.org/security/vulnerabilities_24.html
Acknowledgments
Adobe would like to thank the following for reporting these issues and for working with Adobe to help protect our customers:
- green-jam - CVE-2026-48253, CVE-2026-48254, CVE-2026-48255, CVE-2026-48257, CVE-2026-48260, CVE-2026-48261, CVE-2026-48262
- Dylan Pindur, Adam Kues, and Patrik Grobshäuser of Assetnote - CVE-2026-48252, CVE-2026-48259, CVE-2026-48263, CVE-2026-48310, CVE-2026-48355, CVE-2026-48359
NOTE: Adobe has a public bug bounty program with HackerOne. If you are interested in working with Adobe as an external security researcher, please check out https://hackerone.com/adobe
Revisions
December 18, 2025: Added CVE-2025-64538
December 10, 2025: Removed CVE-2025-64540
December 24, 2025: Added note - "AEM 6.5 and LTS versions are not impacted by the following CVEs: CVE-2025-64537, CVE-2025-64538, CVE-2025-64539."
詳しくは、https://helpx.adobe.com/jp/security.htmlを参照するか、PSIRT@adobe.com 宛てに電子メールでお問い合わせください。