{"id":"CVE-2026-81999","published":"2026-09-22T19:16:53.170","lastModified":"2026-09-23T04:17:53.123","description":"Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.","cvssScore":8.7,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N","cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a Server-Side Request Forgery (SSRF) vulnerability in Adobe Experience Manager Forms JEE that could allow attackers with high privileges to gain elevated access to internal resources. This matters because it can lead to unauthorized access and data exposure.","exploitability":"Exploitation requires high privileges and does not need user interaction, making it moderately hard to exploit.","blast_radius":"If exploited, the impact could be significant as it allows attackers to access internal resources, potentially leading to data breaches or further attacks.","remediation":"Upgrade to the latest version of Adobe Experience Manager Forms JEE.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["ssrf","privilege-escalation","web","internal-access"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:25:13.013Z"}}