CVE-2026-75745 Overview
CVE-2026-75745 is an Incorrect Authorization vulnerability [CWE-863] in Adobe Experience Manager (AEM) Forms JEE. An unauthenticated remote attacker can exploit the flaw to execute arbitrary code in the context of the current user. Exploitation requires no user interaction and results in a scope change, allowing the attacker to impact resources beyond the vulnerable component. Adobe published Security Advisory APSB26-151 addressing the issue.
Critical Impact
Network-reachable AEM Forms JEE deployments can be fully compromised without authentication, leading to arbitrary code execution and lateral movement across trust boundaries.
Affected Products
- Adobe Experience Manager Forms JEE
- Refer to Adobe advisory APSB26-151 for exact affected versions
- Refer to Adobe advisory APSB26-151 for exact patched versions
Discovery Timeline
- 2026-09-22 - CVE CVE-2026-75745 published to NVD
- 2026-09-22 - Last updated in NVD database
- Reference - Adobe Security Advisory APSB26-151
Technical Details for CVE-2026-75745
Vulnerability Analysis
The vulnerability stems from incorrect authorization logic within Adobe Experience Manager Forms JEE. The affected component fails to correctly verify that a requesting principal is permitted to perform a privileged action. Attackers can invoke sensitive functionality reachable over the network without presenting valid credentials.
Because the scope changes during exploitation, the attacker can affect resources outside the vulnerable component's security authority. In AEM Forms JEE deployments, this typically means impacting the underlying application server, adjacent services, and downstream integrations. The result is arbitrary code execution in the context of the current user running the AEM Forms JEE process.
The issue is categorized under [CWE-863] Incorrect Authorization. This class of flaw occurs when access control decisions are made against incorrect assumptions about identity, role, or resource ownership.
Root Cause
The root cause is missing or flawed authorization enforcement on a network-accessible interface within AEM Forms JEE. Adobe's advisory APSB26-151 categorizes the defect as Incorrect Authorization leading to arbitrary code execution. Details on the specific endpoint and code path are not publicly documented.
Attack Vector
The attack vector is network-based. An unauthenticated attacker sends a crafted request to an exposed AEM Forms JEE endpoint. Because no privileges or user interaction are required, mass exploitation of internet-facing servers is feasible once technical details or proof-of-concept code become available. The EPSS score is 1.166% (percentile 65.9) as of 2026-09-24.
No public proof-of-concept or in-the-wild exploitation has been confirmed at the time of publication. Consult the Adobe Security Advisory APSB26-151 for vendor-provided technical context.
Detection Methods for CVE-2026-75745
Indicators of Compromise
- Unexpected child processes spawned by the AEM Forms JEE application server process (for example, java spawning sh, cmd.exe, powershell.exe, or bash).
- New or modified JSP, servlet, or class files under AEM Forms JEE web application directories.
- Outbound network connections from the AEM Forms JEE host to unfamiliar IP addresses or command-and-control infrastructure.
- Anomalous HTTP requests to AEM Forms JEE endpoints from unauthenticated sources, particularly those returning HTTP 200 for administrative or form-processing paths.
Detection Strategies
- Baseline the AEM Forms JEE process tree and alert on any deviation, especially interactive shells or scripting interpreters as children of the JEE container.
- Inspect HTTP access logs for high-volume or repeated requests to AEM Forms JEE endpoints from single source IPs without prior authentication.
- Correlate file-write events in web application directories with subsequent process execution events.
Monitoring Recommendations
- Forward AEM Forms JEE application server logs, HTTP access logs, and host EDR telemetry to a centralized SIEM for correlation.
- Monitor authentication and authorization decision logs for anomalies, including successful privileged operations without a preceding authentication event.
- Track egress traffic from AEM Forms JEE hosts and alert on connections to non-approved destinations.
How to Mitigate CVE-2026-75745
Immediate Actions Required
- Apply the security update referenced in Adobe Security Advisory APSB26-151 to all AEM Forms JEE instances.
- Inventory internet-exposed AEM Forms JEE deployments and restrict network access to trusted management networks until patched.
- Review AEM Forms JEE hosts for indicators of compromise given the unauthenticated, network-based nature of the flaw.
- Rotate credentials, API keys, and secrets stored on or accessible from AEM Forms JEE hosts if compromise is suspected.
Patch Information
Adobe released fixes for this vulnerability in APSB26-151. Administrators should consult the advisory for the exact affected and fixed versions, then apply the vendor-supplied update through their standard AEM Forms JEE patch process. Validate the patched version after installation and confirm the update covers the JEE variant specifically, as AEM Forms has multiple product lines.
Workarounds
- Place AEM Forms JEE endpoints behind a web application firewall configured to block unauthenticated access to administrative and form-processing paths.
- Enforce network-layer access controls that restrict inbound traffic to AEM Forms JEE to known, trusted client ranges.
- Disable or restrict any non-essential AEM Forms JEE services and endpoints until patching is complete.
# Example: restrict inbound access to AEM Forms JEE with iptables
# Replace TRUSTED_CIDR with your management network range
iptables -A INPUT -p tcp --dport 4502 -s TRUSTED_CIDR -j ACCEPT
iptables -A INPUT -p tcp --dport 4502 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.