Impact
Adobe Experience Manager Forms JEE suffers from an incorrect authorization flaw that allows an attacker to execute arbitrary code in the context of the user who authenticates to the application. The vulnerability does not require user interaction and results in a scope change, meaning that the attacker’s privileges are elevated beyond those originally granted. The description explicitly notes that exploitation leads to arbitrary code execution, indicating that any code in the application context could be run.
Affected Systems
The affected products are Adobe Experience Manager Forms JEE version 6.5 and the 6.5 LTS release. No specific sub‑version details are provided, so all installed instances of these products remain potentially vulnerable.
Risk and Exploitability
With a CVSS score of 10, the flaw is considered critical. The EPSS score is not available, making it unclear how often attackers target this vulnerability, but the lack of user interaction suggests it could be exploited remotely once an authenticated session is established. The issue is not listed in the CISA KEV catalog, so no publicly known exploit is currently tracked. Attackers would need to identify a legitimate or compromised account with access to the Forms management console or send crafted requests to the vulnerable endpoints; the incorrect authorization permits any such attempt to execute code with the privileges of the current user.
OpenCVE Enrichment