Junglewise Threat Intelligence

CVE-2026-75743: Adobe Experience Manager Forms JEE cross-site request forgery

CVE-2026-75743 · Severity: high · CVSS 7.1 · Published 2026-09-22

Technologies: Adobe Experience Manager Forms JEE. Vendors: Adobe.

Executive brief

Adobe Experience Manager Forms JEE, a platform for building data capture and document management workflows, is vulnerable to cross-site request forgery (CSRF) attacks. An attacker could trick a user into visiting a malicious website to perform unauthorized actions like modifying form configurations or settings. Successful exploitation requires user interaction and could bypass security controls, leading to unauthorized data access and limited system disruption.

Technical details

This CSRF vulnerability in Experience Manager Forms JEE allows an attacker to forge requests that execute actions on behalf of an authenticated user without their knowledge. The attack requires social engineering (victim visits a malicious URL or compromised page) and results in security feature bypass with unauthorized write access. A fix is expected to be available from Adobe.

Affected products

  • Adobe Experience Manager Forms JEE

Timeline

  • 2026-09-22: disclosed

References

Related threats