Executive brief
Adobe Experience Manager Forms JEE, a platform used by organizations to create and manage complex digital forms and document workflows, is affected by a security vulnerability. An attacker could use this flaw to execute malicious scripts in a user's browser if the user clicks on a specially crafted link. This could lead to the attacker gaining unauthorized access to the user's session or sensitive account information.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager Forms JEE (versions 6.5.24.0 and earlier, including LTS SP1). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by enticing a user to visit a maliciously crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to credential theft or unauthorized actions. The attack complexity is rated as high, suggesting specific environmental conditions or configurations are required for successful exploitation.
Affected products
- Adobe Experience Manager Forms JEE LTS SP1, 6.5.24.0 and earlier
Timeline
- 2026-06-09: advisory: Adobe published security bulletin APSB26-57
- 2026-06-09: disclosed: CVE-2026-34693 published to NVD