Junglewise Threat Intelligence

CVE-2026-34660: Adobe Connect incorrect authorization in Desktop Application

CVE-2026-34660 · Severity: critical · CVSS 9.3 · Published 2026-05-12

Vendors: Adobe.

Executive brief

Adobe Connect, a platform used for web conferencing and remote training, is affected by a security flaw that allows attackers to execute unauthorized code. By tricking a user into clicking a malicious link or visiting a compromised website, an attacker can inject scripts into the user's session. This could lead to the attacker gaining full control over the victim's account, accessing sensitive meeting data, or performing actions on the user's behalf.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Adobe Connect Desktop Application versions up to 2025.9.15 (Windows) and 2025.8.157 (macOS). The flaw allows a remote, unauthenticated attacker to execute arbitrary code or inject malicious scripts into the web context of the application. Exploitation requires user interaction, specifically that a victim visits a maliciously crafted URL or interacts with a compromised web page. Because the vulnerability results in a 'Scope Change' (S:C) in the CVSS metric, the injected scripts can bypass security boundaries to gain elevated access or control over the victim's session. Adobe has addressed this in security bulletin APSB26-50.

Affected products

  • Adobe Connect Desktop Application 2025.9.15 (Windows), 2025.8.157 (macOS) and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Adobe security bulletin APSB26-50 published

References