Junglewise Threat Intelligence

CVE-2026-82000: Adobe Experience Manager Forms JEE server-side request forgery

CVE-2026-82000 · Severity: critical · CVSS 9.6 · Published 2026-09-22

Technologies: Adobe Experience Manager Forms JEE. Vendors: Adobe.

Executive brief

Adobe Experience Manager Forms JEE contains a server-side request forgery (SSRF) vulnerability that allows an attacker with low-level access to make unauthorized requests on behalf of the server, potentially reaching internal systems and escalating privileges. The vulnerability requires no user interaction to exploit and can result in attackers gaining unauthorized access to sensitive internal resources and elevated system capabilities.

Technical details

An SSRF vulnerability in Adobe Experience Manager Forms JEE allows a low-privileged attacker to issue arbitrary requests from the vulnerable server without user interaction. This enables access to internal resources and systems that would normally be restricted from external or low-privilege access. The vulnerability has been assigned a critical severity rating with a CVSS score of 9.6.

Affected products

  • Adobe Experience Manager Forms JEE

Timeline

  • 2026-09-22: disclosed

References

Related threats