Description
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery enabling privilege escalation
Action: Apply patch immediately
AI Analysis

Impact

Adobe Experience Manager Forms JEE is vulnerable to server‑side request forgery that allows an attacker with high privileges to instruct the server to send requests to arbitrary internal resources, potentially accessing data or services that should be isolated. This flaw, marked as having changed scope, can thus affect a broader set of system components.

Affected Systems

Adobe Experience Manager 6.5 Forms JEE and Adobe Experience Manager 6.5 LTS Forms JEE are affected. No specific version information is listed, so any deployment of these products could be vulnerable unless the latest Adobe patch is applied.

Risk and Exploitability

The CVSS score of 8.7 reflects a high severity risk, and the EPSS score is not available, indicating that exploitation frequency is not quantified but the flaw remains significant. The issue does not require user interaction, making automated exploitation possible, and it is not listed in the CISA KEV catalog. Attackers with sufficient privileges can leverage the SSRF to reach internal services, potentially escalating privileges.

Generated by OpenCVE AI on September 22, 2026 at 21:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe AEM Forms JEE security fix published in the Adobe security advisory (https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html).
  • If the patch cannot be applied immediately, restrict outbound traffic from the AEM Forms JEE servers to only allowed destinations via firewall or network segmentation to limit potential SSRF exploitation.
  • Monitor the application logs and network traffic for unexpected outbound requests from AEM Forms JEE to detect possible abuse or attempted lateral movement.

Generated by OpenCVE AI on September 22, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T19:12:40.983Z

Reserved: 2026-08-27T21:20:45.367Z

Link: CVE-2026-81999

cve-icon Vulnrichment

Updated: 2026-09-22T19:12:32.353Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:53.170

Modified: 2026-09-22T20:17:09.227

Link: CVE-2026-81999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:15:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)