Executive brief
Adobe Connect, a web conferencing platform used for online meetings and webinars, is affected by a security flaw that allows attackers to run malicious code in a user's browser. To exploit this, an attacker must trick a user into clicking a specially crafted link. If successful, the attacker could potentially steal session information or perform actions on behalf of the user within the application.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Adobe Connect versions 12.10, 2025.3, and earlier. The flaw stems from improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by inducing a user to visit a malicious URL containing injected scripts. Successful exploitation results in the execution of arbitrary JavaScript within the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. The vulnerability is characterized by a changed scope (S:C) in the CVSS metric.
Affected products
- Adobe Connect 12.10 and earlier, 2025.3 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory