CVE-2024-26029: Adobe Experience Manager | Improper Access Control (CWE-284)
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain disclose information. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26029?
CVE-2024-26029 is classified as a medium severity vulnerability due to its potential for security feature bypass.
How do I fix CVE-2024-26029?
To mitigate CVE-2024-26029, upgrade Adobe Experience Manager to version 6.5.21 or later.
What versions of Adobe Experience Manager are affected by CVE-2024-26029?
CVE-2024-26029 affects Adobe Experience Manager versions 6.5.20 and earlier, including AEM Cloud Service prior to version 2024.5.
What types of attacks does CVE-2024-26029 enable?
Exploitation of CVE-2024-26029 allows attackers to bypass security measures and potentially disclose sensitive information.
Is there a patch available for CVE-2024-26029?
Yes, Adobe has released a patch for CVE-2024-26029 in version 6.5.21 and later.