Junglewise Threat Intelligence

CVE-2026-75744: Adobe Experience Manager Forms JEE stored XSS in form fields

CVE-2026-75744 · Severity: high · CVSS 8.1 · Published 2026-09-22

Technologies: Adobe Experience Manager Forms JEE. Vendors: Adobe.

Executive brief

Adobe Experience Manager Forms JEE, a platform for designing and managing enterprise forms, is vulnerable to stored cross-site scripting (XSS) attacks. A high-privileged attacker can inject malicious scripts into form fields that execute when other users view the form, potentially compromising their accounts or sessions. This vulnerability changes the scope of what an attacker can access after exploitation.

Technical details

The vulnerability is a stored XSS flaw in Adobe Experience Manager Forms JEE where unsanitized user input in form fields is persisted and executed in victims' browsers. Exploitation requires high-privilege attacker access to inject the malicious payload, and the attack succeeds when a victim visits the page containing the compromised form field. Successful exploitation allows arbitrary JavaScript execution in the victim's browser context, potentially leading to session hijacking or privilege escalation.

Affected products

  • Adobe Experience Manager Forms JEE

Timeline

  • 2026-09-22: disclosed

References

Related threats