Executive brief
Adobe Experience Manager Forms JEE, a server for building and managing enterprise forms, is vulnerable to a server-side request forgery (SSRF) attack that allows attackers with high privileges to gain elevated access to internal systems. An attacker could exploit this to compromise sensitive internal resources without requiring user interaction, leading to unauthorized access to backend systems and data.
Technical details
The vulnerability is a server-side request forgery (SSRF) in Adobe Experience Manager Forms JEE that permits privilege escalation. An attacker with high-privilege credentials can bypass access controls to reach internal resources. The attack vector is network-based, does not require user interaction, and results in scope change allowing access beyond the intended application boundary.
Affected products
- Adobe Experience Manager Forms JEE
Timeline
- 2026-09-22: disclosed