CVE-2026-47991: Adobe Experience Manager | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47991?
CVE-2026-47991 has a medium severity rating of 4.3.
How do I fix CVE-2026-47991?
To fix CVE-2026-47991, update Adobe Experience Manager to the latest version beyond 6.5.24, LTS SP1, or 2026.04.
What types of attacks can occur due to CVE-2026-47991?
CVE-2026-47991 can allow attackers to perform account takeover attacks through open redirects to untrusted sites.
Which versions of Adobe Experience Manager are affected by CVE-2026-47991?
Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by CVE-2026-47991.
Is user intervention required to exploit CVE-2026-47991?
Yes, user interaction is required to exploit CVE-2026-47991 as it involves clicking on a malicious link.