Executive brief
Adobe Connect, a web-based meeting and collaboration platform, contains a path traversal vulnerability that allows an attacker to read arbitrary files from the server's file system. An attacker can bypass directory restrictions and access sensitive files without requiring user interaction or authentication, potentially exposing configuration files, credentials, and other confidential data.
Technical details
The vulnerability is an improper limitation of pathname input (CWE-22 path traversal) that allows attackers to traverse directory boundaries and read files outside the intended access scope. The issue does not require user interaction or authentication and changes the security scope of the affected system, indicating impact beyond the normal operational boundaries.
Affected products
- Adobe Connect <UNKNOWN>
Timeline
- 2026-09-22: disclosed