Executive brief
Adobe Experience Manager Forms JEE, a platform for building data capture and document management workflows, is vulnerable to cross-site request forgery (CSRF) attacks. An attacker could trick a user into visiting a malicious website to perform unauthorized actions like modifying form configurations or settings. Successful exploitation requires user interaction and could bypass security controls, leading to unauthorized data access and limited system disruption.
Technical details
This CSRF vulnerability in Experience Manager Forms JEE allows an attacker to forge requests that execute actions on behalf of an authenticated user without their knowledge. The attack requires social engineering (victim visits a malicious URL or compromised page) and results in security feature bypass with unauthorized write access. A fix is expected to be available from Adobe.
Affected products
- Adobe Experience Manager Forms JEE
Timeline
- 2026-09-22: disclosed