Executive brief
Adobe Experience Manager Forms JEE, a platform used by organizations to create and manage complex digital forms, is affected by a security vulnerability. A high-privileged user can embed malicious scripts into form fields that will execute in the browsers of other users who view those forms. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Experience Manager Forms JEE (versions LTS SP1, 6.5.24.0 and earlier) due to improper neutralization of input during web page generation (CWE-79). An attacker with high privileges can inject malicious JavaScript into specific form fields. When a victim subsequently navigates to the page containing the compromised field, the script executes within the context of the victim's browser session. The vulnerability has a CVSS score of 5.9, reflecting that while it requires high privileges and user interaction, the security scope is changed, potentially impacting other components. Users are advised to refer to Adobe security bulletin APSB26-57 for patching information.
Affected products
- Adobe Experience Manager Forms JEE LTS SP1, 6.5.24.0 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory