Medium severity5.9NVD Advisory· Published Jun 9, 2026· Updated Jun 11, 2026
CVE-2026-34694
CVE-2026-34694
Description
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected products
4cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*range: <=6.5.24.0
- cpe:2.3:a:adobe:experience_manager:6.5:-:*:*:lts:*:*:*
- cpe:2.3:a:adobe:experience_manager:6.5:sp1:*:*:lts:*:*:*
- Range: <=6.5.24.0 (including LTS SP1)
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/aem-forms/apsb26-57.htmlnvdVendor Advisory
News mentions
1- Adobe Experience Manager: 25 Vulnerabilities Disclosed, Mostly XSS and Memory CorruptionVypr Intelligence · Jun 9, 2026