CSRF Vulnerability in Adobe Experience Manager Forms JEE
CVE-2026-75743

7.1HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
22 September 2026

What is CVE-2026-75743?

Adobe Experience Manager Forms JEE is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that can enable unauthorized security feature bypass. This flaw allows attackers to potentially gain unauthorized write access to the system, contingent upon the victim's interaction with a maliciously crafted URL or compromised webpage. This interaction could lead to limited disruptions in availability as the security measures in place can be circumvented.

Affected Version(s)

AEM 6.5 Forms JEE 0 <= 6.5.25

AEM 6.5 LTS Forms JEE 0 <= 6.5 LTS SP2

AEM 6.5 Forms JEE 6.5.25 (AEMForms-6.5.0-0134 Hotfix)

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.