{"id":"CVE-2026-82000","published":"2026-09-22T19:16:53.297","lastModified":"2026-09-23T13:17:30.377","description":"Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.","cvssScore":9.6,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a Server-Side Request Forgery (SSRF) vulnerability in Adobe Experience Manager Forms JEE that allows a low-privileged attacker to gain elevated access to internal resources, potentially leading to privilege escalation.","exploitability":"Exploitation requires the attacker to have low privileges and does not require user interaction, making it relatively easy to exploit once the attacker gains initial access.","blast_radius":"If exploited, the vulnerability could allow an attacker to access internal resources, potentially leading to significant data exposure or system compromise.","remediation":"Upgrade to the latest version of Adobe Experience Manager Forms JEE as no specific fixed version is mentioned in the description.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["ssrf","privilege-escalation","web","java"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:53:53.987Z"}}