Junglewise Threat Intelligence

CVE-2026-75745: Adobe Experience Manager Forms JEE authorization bypass

CVE-2026-75745 · Severity: critical · CVSS 10 · Published 2026-09-22

Technologies: Adobe Experience Manager Forms JEE. Vendors: Adobe.

Executive brief

Adobe Experience Manager Forms JEE is a document and form management system used by enterprises to create and process business-critical forms. An authorization vulnerability in this product allows attackers to execute arbitrary code without user interaction, potentially compromising the entire Forms JEE instance and any data it processes.

Technical details

An incorrect authorization flaw in Adobe Experience Manager Forms JEE permits unauthenticated or low-privileged attackers to bypass access controls and achieve arbitrary code execution in the context of the application. The vulnerability requires network access but no user interaction; scope changes indicate a jump from the vulnerable component to other system components. A patch is expected from Adobe given the reported severity.

Affected products

  • Adobe Experience Manager Forms JEE

Timeline

  • 2026-09-22: disclosed

References

Related threats