CVE-2026-82000
Last modified
CVE-2026-82000 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources.
Description
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Adobe | AEM 6.5 Forms JEE | <= 6.5.25 |
| Adobe | AEM 6.5 LTS Forms JEE | <= 6.5 LTS SP2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-82000?
How severe is CVE-2026-82000?
How do I fix CVE-2026-82000?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81995Adobe Experience Manager Forms JEE is affected by an Imprope…9.1
- CVE-2026-81996Acrobat Reader is affected by an Incorrect Authorization vul…8.8
- CVE-2026-81997Acrobat Reader is affected by an Incorrect Authorization vul…6.3
- CVE-2026-81998Substance3D - Modeler is affected by an out-of-bounds write …7.8
- CVE-2026-81999Adobe Experience Manager Forms JEE is affected by a Server-S…8.7
- CVE-2026-8200When schema validation is enabled on a collection and an upd…5.3
- CVE-2026-82001Acrobat Reader is affected by an Uncontrolled Resource Consu…5.5
- CVE-2026-82003Adobe Campaign Classic (ACC) is affected by an Improper Inpu…8.5
- CVE-2026-82004Adobe Campaign Classic (ACC) is affected by an Improper Neut…10
- CVE-2026-82005Photoshop Desktop is affected by an out-of-bounds write vuln…7.8
- CVE-2026-82006Photoshop Desktop is affected by a Heap-based Buffer Overflo…7.8
- CVE-2026-82007Photoshop Desktop is affected by an Integer Overflow or Wrap…7.8
Are you affected by CVE-2026-82000?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
