CVE-2021-28626: Adobe Experience Manager Improper Authorization at /content/usergenerated
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by an Improper Authorization vulnerability allowing users to create nodes under a location. An unauthenticated attacker could leverage this vulnerability to cause an application denial-of-service. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-28626.
What is the severity of CVE-2021-28626?
The severity of CVE-2021-28626 is high with a CVSS score of 7.5.
What is the affected software for CVE-2021-28626?
The affected software for CVE-2021-28626 is Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below).
What is the description of CVE-2021-28626?
CVE-2021-28626 is an Improper Authorization vulnerability in Adobe Experience Manager Cloud Service offering and versions 6.5.8.0 (and below) that allows unauthenticated users to create nodes under a location, potentially leading to application denial-of-service.
How can an attacker leverage CVE-2021-28626?
An unauthenticated attacker could leverage CVE-2021-28626 to cause an application denial-of-service.