Executive brief
Adobe Experience Manager Forms JEE, a platform used by organizations to create and manage complex digital forms, is affected by a security vulnerability. An attacker can inject malicious scripts into form fields that are then saved on the server. When other users or administrators view these forms, the scripts execute in their browser, potentially allowing the attacker to steal session information or take control of the victim's account.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager Forms JEE due to improper neutralization of input during web page generation (CWE-79). An unauthenticated remote attacker can inject malicious JavaScript into vulnerable form fields. This script is stored on the server and executes in the context of any user who subsequently views the affected page. Because the vulnerability has a 'Changed' scope (S:C) and high impact on confidentiality and integrity, it can be used to bypass same-origin policies and gain elevated access to victim sessions. Users are advised to update to the latest patched versions as specified in Adobe advisory APSB26-57.
Affected products
- Adobe Experience Manager Forms JEE LTS SP1, 6.5.24.0 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory