CVE-2026-75743: Adobe Experience Manager Forms JEE | Cross-Site Request Forgery (CSRF) (CWE-352)
Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker must persuade a victim to visit a maliciously crafted URL or interact with a compromised web page. No attacker privileges are required.
Who is realistically exposed to this attack?
Users of Adobe Experience Manager Forms JEE who can be induced to interact with attacker-controlled web content are exposed. The issue is remotely exploitable and requires victim interaction.