CVE-2026-75684

Summary

Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

Affected Software

VendorProductVersion RangeStatus
AdobeAdobe Connect0 <= 12.11affected
AdobeAdobe Connect12.11.1, 12.12unaffected
AdobeAdobe Connect Android Mobile App0 <= 4.4affected
AdobeAdobe Connect Android Mobile App4.5unaffected

Weaknesses

  • CWE-79: Cross-site Scripting (Stored XSS) (CWE-79)

References