Server-Side Request Forgery in Adobe Experience Manager Forms JEE
CVE-2026-82000

9.6CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
22 September 2026

What is CVE-2026-82000?

Adobe Experience Manager Forms JEE is susceptible to a Server-Side Request Forgery (SSRF) vulnerability that can lead to privilege escalation. This flaw allows a low-privileged attacker to exploit the system, gaining unauthorized access to internal resources without needing user interaction. This change in the scope of access highlights the potential risks associated with this vulnerability.

Affected Version(s)

AEM 6.5 Forms JEE 0 <= 6.5.25

AEM 6.5 LTS Forms JEE 0 <= 6.5 LTS SP2

AEM 6.5 Forms JEE 6.5.25 (AEMForms-6.5.0-0134 Hotfix)

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.