Junglewise Threat Intelligence

CVE-2026-34689: Adobe Connect path traversal in file access

CVE-2026-34689 · Severity: high · CVSS 8.6 · Published 2026-09-22

Technologies: Apple macOS, Microsoft Windows, Adobe Connect For Mobile, Adobe Connect. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe Connect, a web-based meeting and collaboration platform, contains a path traversal vulnerability that allows an attacker to read arbitrary files from the server's file system. An attacker can bypass directory restrictions and access sensitive files without requiring user interaction or authentication, potentially exposing configuration files, credentials, and other confidential data.

Technical details

The vulnerability is an improper limitation of pathname input (CWE-22 path traversal) that allows attackers to traverse directory boundaries and read files outside the intended access scope. The issue does not require user interaction or authentication and changes the security scope of the affected system, indicating impact beyond the normal operational boundaries.

Affected products

  • Adobe Connect <UNKNOWN>

Timeline

  • 2026-09-22: disclosed

References

Related threats