CVE-2026-34693: Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34693?
CVE-2026-34693 has a severity rating of high with a score of 8.
How do I fix CVE-2026-34693?
To fix CVE-2026-34693, update Adobe Experience Manager Forms JEE to the latest version available after LTS SP1 and 6.5.24.0.
What types of attacks can exploit CVE-2026-34693?
CVE-2026-34693 can be exploited through reflected Cross-Site Scripting attacks, allowing attackers to inject malicious scripts.
What versions are affected by CVE-2026-34693?
CVE-2026-34693 affects Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier.
What is the impact of successfully exploiting CVE-2026-34693?
Exploiting CVE-2026-34693 could allow an attacker to gain elevated access or control over the victim's session.