Executive brief
Adobe Experience Manager Forms JEE, a platform for building enterprise forms and data capture applications, contains an input validation flaw that allows attackers with high-level privileges to execute arbitrary code on the server. This can lead to complete compromise of the forms application and access to sensitive business data, with no user interaction required to trigger the attack.
Technical details
The vulnerability stems from improper input validation in Adobe Experience Manager Forms JEE, allowing an authenticated attacker with elevated privileges to inject and execute arbitrary code within the application context. No user interaction is required for exploitation, though the attacker must have high-level system privileges to launch the attack. A fix is expected from Adobe.
Affected products
- Adobe Experience Manager Forms JEE
Timeline
- 2026-09-22: disclosed