Executive brief
Adobe Connect, a web conferencing and collaboration platform used by organizations to host meetings and training sessions, contains a stored cross-site scripting (XSS) vulnerability in form fields. An attacker can inject malicious JavaScript code that will execute in the browsers of any user who views the affected page, potentially allowing them to steal session credentials, redirect users to malicious sites, or perform actions on behalf of the victim.
Technical details
Adobe Connect is vulnerable to stored XSS in form fields that do not properly sanitize user-supplied input. An unauthenticated or authenticated attacker can inject malicious JavaScript that persists in the application and executes when other users access the compromised form. The vulnerability changes the scope of the application, allowing attackers to break out of the intended security boundary.
Affected products
- Adobe Connect
Timeline
- 2026-09-22: disclosed