Executive brief
Adobe Connect, a platform used for web conferencing and remote training, is affected by a security flaw that allows attackers to execute unauthorized code. By tricking a user into clicking a malicious link or visiting a compromised website, an attacker can inject scripts into the user's session. This could lead to the attacker gaining full control over the victim's account, accessing sensitive meeting data, or performing actions on the user's behalf.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Adobe Connect Desktop Application versions up to 2025.9.15 (Windows) and 2025.8.157 (macOS). The flaw allows a remote, unauthenticated attacker to execute arbitrary code or inject malicious scripts into the web context of the application. Exploitation requires user interaction, specifically that a victim visits a maliciously crafted URL or interacts with a compromised web page. Because the vulnerability results in a 'Scope Change' (S:C) in the CVSS metric, the injected scripts can bypass security boundaries to gain elevated access or control over the victim's session. Adobe has addressed this in security bulletin APSB26-50.
Affected products
- Adobe Connect Desktop Application 2025.9.15 (Windows), 2025.8.157 (macOS) and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Adobe security bulletin APSB26-50 published