216.73.217.22

CVE-2026-34691

· Published 09/06/2026 18:16 · Modified 09/06/2026 19:30

Labels: CVE-2026-34691 2026-06-09CVE-2026-34691CWE-79[email protected]

Essential information

Published
09/06/2026 18:16
Modified
09/06/2026 19:30
Author
Creator
CVSS
9.3 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CVSS metrics

Description

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
adobe / experience manager forms cpe:2.3:a:adobe:experience_manager_forms:<=6.5.24.0:*:*:*:*:*:*:*

References