Executive brief
Adobe Connect, a web conferencing and remote training platform, is affected by a security vulnerability that could allow an attacker to execute unauthorized commands. By tricking a user into visiting a malicious link, an attacker could take control of the user's session or inject malicious scripts into the application. This could lead to the theft of sensitive information or unauthorized access to private meetings and data.
Technical details
A Deserialization of Untrusted Data vulnerability (CWE-502) exists in Adobe Connect versions 12.10, 2025.3, and earlier. The flaw occurs when the application processes maliciously crafted serialized data provided by a remote user. An attacker can exploit this by inducing a victim to visit a specially crafted URL or interact with a compromised web page. Successful exploitation allows for arbitrary code execution in the context of the victim's session and the injection of malicious scripts, potentially leading to full account takeover or session hijacking. Adobe has addressed this in newer versions (e.g., 12.11 and 2025.9.15).
Affected products
- Adobe Connect 12.10 and earlier, 2025.3 and earlier
Timeline
- 2026-04-14: advisory: Initial advisory published by Adobe
- 2026-04-14: disclosed