CRITICAL🇵🇱 Wersja polska

CVE-2026-34691

CVSS 9.3v3.1pub. 2026-06-09upd. 2026-08-28

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

🤖 AI Analysis
How it works

The vulnerability consists of insufficient input sanitization in form fields of the AEM Forms JEE application. An unauthenticated attacker, but requiring user interaction (UI:R), injects malicious JavaScript into a vulnerable form field, where it is permanently stored (stored XSS). When the victim visits the page containing the infected field, the script is automatically executed in their browser within the application context. The scope change means that the effects extend beyond the vulnerable component itself.

Impact

An attacker can execute arbitrary JavaScript code in the victim's browser, enabling session hijacking, credential theft, privilege escalation, or takeover of user accounts. The high impact on confidentiality and integrity makes this threat particularly serious in corporate environments handling sensitive forms.

Mitigation & patch

Patches available from the vendor should be applied according to references — the official Adobe security bulletin is available at: https://helpx.adobe.com/security/products/aem-forms/apsb26-57.html

Who is affected

Adobe Experience Manager Forms JEE in LTS SP1 version, 6.5.24.0 and earlier versions

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Adobe Experience Manager

    APP
    Adobe
    6.5≤ 6.5.24.0
  • Apple iOS

    OS
    Apple
    all versions
  • Apple macOS

    OS
    Apple
    all versions
  • Google Android

    OS
    Google
    all versions
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP