CVE-2026-75744

8.1

Adobe · AEM 6.5 Forms JEE

Adobe AEM 6.5 Forms JEE is vulnerable to stored Cross-Site Scripting (XSS) that allows high-privileged attackers to inject malicious scripts into forms, potentially compromising victim sessions.

Executive summary

Adobe AEM 6.5 Forms JEE contains a stored Cross-Site Scripting vulnerability that enables high-privileged attackers to execute arbitrary JavaScript in the context of other users' browser sessions.

Vulnerability

This is a stored Cross-Site Scripting (CWE-79) vulnerability occurring within form fields. An attacker with high privileges can inject malicious scripts which execute when a victim accesses the affected page, leading to potential session hijacking or unauthorized administrative actions.

Business impact

The exploitation of this vulnerability could lead to significant unauthorized access, as the execution of malicious scripts in a victim's browser can bypass standard authentication controls. Given the CVSS score of 8.1, this is a high-severity risk that could result in the compromise of sensitive organizational data or the manipulation of critical business processes managed through AEM Forms.

Remediation

Immediate Action: Update Adobe AEM 6.5 Forms JEE to version 6.5.25 (applying AEMForms-6.5.0-0134 Hotfix) or upgrade AEM 6.5 LTS Forms JEE to SP3 immediately.

Proactive Monitoring: Review web server and application logs for suspicious script injection patterns within form data fields or unusual client-side activity originating from administrative accounts.

Compensating Controls: Implement a robust Content Security Policy (CSP) to restrict the execution of unauthorized scripts and utilize a Web Application Firewall (WAF) to filter malicious input patterns commonly associated with XSS attacks.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations should prioritize the application of the vendor-provided hotfix or service pack to remediate this vulnerability. Because the flaw allows for the execution of scripts in the context of other users, failure to patch may lead to unauthorized administrative control over the AEM environment.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources