Improper Input Validation in Adobe Experience Manager Forms JEE
CVE-2026-81995

9.1CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
22 September 2026

What is CVE-2026-81995?

Adobe Experience Manager Forms JEE contains a vulnerability resulting from improper input validation. This flaw allows an attacker, authorized with high privileges, to execute arbitrary code within the context of the current user without needing user interaction. The exploitation of this vulnerability can lead to significant security risks, as the scope of the attack can be altered, making it critical for users to address this flaw promptly.

Affected Version(s)

AEM 6.5 Forms JEE 0 <= 6.5.25

AEM 6.5 LTS Forms JEE 0 <= 6.5 LTS SP2

AEM 6.5 Forms JEE 6.5.25 (AEMForms-6.5.0-0134 Hotfix)

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.