Junglewise Threat Intelligence

CVE-2026-81999: Adobe Experience Manager Forms JEE server-side request forgery

CVE-2026-81999 · Severity: high · CVSS 8.7 · Published 2026-09-22

Technologies: Adobe Experience Manager Forms JEE. Vendors: Adobe.

Executive brief

Adobe Experience Manager Forms JEE, a server for building and managing enterprise forms, is vulnerable to a server-side request forgery (SSRF) attack that allows attackers with high privileges to gain elevated access to internal systems. An attacker could exploit this to compromise sensitive internal resources without requiring user interaction, leading to unauthorized access to backend systems and data.

Technical details

The vulnerability is a server-side request forgery (SSRF) in Adobe Experience Manager Forms JEE that permits privilege escalation. An attacker with high-privilege credentials can bypass access controls to reach internal resources. The attack vector is network-based, does not require user interaction, and results in scope change allowing access beyond the intended application boundary.

Affected products

  • Adobe Experience Manager Forms JEE

Timeline

  • 2026-09-22: disclosed

References

Related threats