Description
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation via SSRF
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a Server‑Side Request Forgery that lets a low‑privileged attacker send requests from the server to internal addresses. By abusing this flaw the attacker can access internal resources, read or modify sensitive data, and potentially gain elevated privileges on the system. The attack does not require user interaction and the affected component can change the scope of the compromise.

Affected Systems

Adobe Experience Manager Forms JEE, including AEM 6.5 Forms JEE and AEM 6.5 LTS Forms JEE. No specific patch versions are listed, but any instance of these products is potentially vulnerable.

Risk and Exploitability

The CVSS score of 9.6 indicates a critical severity, and the EPSS score is not available, so specific exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the SSRF by sending crafted requests to internal hosts; once the request is made, the attacker can read responses and potentially manipulate resources until privilege escalation occurs.

Generated by OpenCVE AI on September 22, 2026 at 21:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a fixed release of Adobe Experience Manager Forms JEE.
  • If a patch is unavailable, implement network controls such as firewall rules or proxy restrictions to block the AEM server from contacting internal network resources unless explicitly required.
  • Monitor application logs and network traffic for unexpected outbound requests that may indicate an SSRF attempt.

Generated by OpenCVE AI on September 22, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Title Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-23T03:56:06.619Z

Reserved: 2026-08-27T21:20:45.367Z

Link: CVE-2026-82000

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:53.297

Modified: 2026-09-23T04:17:53.247

Link: CVE-2026-82000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:15:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)