CVE-2026-81999
8.7 HIGHPublished 2026-09-22 · Updated 2026-09-23
AI risk analysis
- Summary
- The flaw is a Server-Side Request Forgery (SSRF) vulnerability in Adobe Experience Manager Forms JEE that could allow attackers with high privileges to gain elevated access to internal resources. This matters because it can lead to unauthorized access and data exposure.
- Exploitability
- Exploitation requires high privileges and does not need user interaction, making it moderately hard to exploit.
- Blast radius
- If exploited, the impact could be significant as it allows attackers to access internal resources, potentially leading to data breaches or further attacks.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the latest version of Adobe Experience Manager Forms JEE.
ssrfprivilege-escalationwebinternal-access
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Weaknesses
CWE-918
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-61749PoC
- CRITICALCVE-2026-82000
- CRITICALCVE-2026-82013
- CRITICALCVE-2026-82443
- CRITICALCVE-2026-83660
- CRITICALCVE-2026-36469PoC
- CRITICALCVE-2026-51994PoC
- MEDIUMCVE-2026-61612PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.