Description
Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Published: 2026-09-22
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

Adobe Experience Manager Forms JEE is vulnerable to a stored Cross‑Site Scripting flaw that enables a high‑privileged attacker to inject malicious JavaScript into form fields. The injected code is persisted and executed whenever a victim loads the affected page, potentially giving the attacker elevated access or control over the victim's account or session. The weakness is a classic input validation failure consistent with CWE‑79.

Affected Systems

The vulnerability affects Adobe Experience Manager 6.5 Forms JEE and its LTS variant, specifically the Forms JEE component. No specific affected version numbers are listed, so all releases of these products should be considered at risk until patched.

Risk and Exploitability

With a CVSS score of 8.1 this vulnerability represents high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, indicating it has not yet been widely exploited. The likely attack vector requires a high‑privileged or privileged user to submit malicious content, which then becomes stored and later executed in an end‑user’s browser. Once the payload is delivered via the stored XSS, it can compromise confidentiality, integrity, and availability of the affected system from the perspective of the victim’s session.

Generated by OpenCVE AI on September 22, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Adobe security patch for AEM 6.5 Forms JEE to remove the stored XSS flaw.
  • If an immediate upgrade is not possible, temporarily remove or disable the vulnerable form fields so new malicious entries cannot be stored.
  • Add server‑side input validation and output encoding for all form fields to neutralize any script payloads until the patch is applied.

Generated by OpenCVE AI on September 22, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Title Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T19:13:18.918Z

Reserved: 2026-08-18T01:29:54.623Z

Link: CVE-2026-75744

cve-icon Vulnrichment

Updated: 2026-09-22T19:13:16.138Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:47.383

Modified: 2026-09-22T20:17:06.280

Link: CVE-2026-75744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:15:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')