SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-34691 2026-06-09

CVE-2026-34691: Critical Stored XSS in Adobe Experience Manager Forms JEE

"A critical stored cross-site scripting flaw in Adobe Experience Manager (AEM) Forms JEE lets an unauthenticated attacker plant malicious JavaScript in form fields that executes in a victim's browser, potentially…"

A critical stored cross-site scripting flaw in Adobe Experience Manager (AEM) Forms JEE lets an unauthenticated attacker plant malicious JavaScript in form fields that executes in a victim's browser, potentially hijacking their account or session.

What Is It

CVE-2026-34691 is a stored Cross-Site Scripting (XSS) vulnerability (CWE-79) in Adobe Experience Manager Forms JEE. An attacker can inject malicious scripts into vulnerable form fields. When a victim browses to the page containing the affected field, the malicious JavaScript executes in their browser, potentially gaining elevated access or control over the victim's account or session. The vulnerability carries a CVSS 3.1 base score of 9.3 (CRITICAL), with a vector of AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N, network-reachable, low complexity, no privileges required, but requiring user interaction. Notably, the scope is changed, meaning impact extends beyond the initially vulnerable component.

Why It Matters

The combination of no required privileges, network attack vector, and a changed scope drives the near-maximal 9.3 score. Successful exploitation yields high confidentiality and integrity impact, allowing an attacker to compromise victim accounts or sessions. Because the script is stored, any user who later views the poisoned form field is exposed; making this a persistent threat to anyone interacting with affected forms. This source material contains no CISA KEV entry, so there is no confirmation of active exploitation at this time.

What's Vulnerable

Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected. No specific affected CPEs were enumerated in the source NVD record.

Patch Status

Adobe published security bulletin APSB26-57 covering this vulnerability. Administrators running AEM Forms JEE LTS SP1 or 6.5.24.0 and earlier should consult the bulletin and apply the vendor's fixes. The NVD record was published 2026-06-09 and remains in "Awaiting Analysis" status. No CISA KEV remediation deadline applies, as there is no KEV entry in the supplied data.

Sources