Executive brief
Adobe Connect, a web conferencing platform used for online meetings and training, is affected by a security flaw that could allow an attacker to take over user sessions. By tricking a user into clicking a malicious link, an attacker can run unauthorized scripts in the user's browser, potentially gaining full control over their account or sensitive meeting data. This could lead to unauthorized access to private communications or administrative functions within the platform.
Technical details
A stored or reflected Cross-Site Scripting (XSS) vulnerability exists in Adobe Connect versions 12.10, 2025.3, and earlier due to improper neutralization of user-supplied input during web page generation (CWE-79). A low-privileged attacker can exploit this by injecting malicious scripts into the application's web interface. Execution occurs when a victim visits a specifically crafted URL or interacts with a compromised page. Because the vulnerability results in a 'Scope Change' (S:C) in the CVSS metric, the injected script can access data or perform actions with the privileges of the victim, potentially leading to full account takeover or administrative privilege escalation.
Affected products
- Adobe Connect 12.10 and earlier, 2025.3 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory