CVE-2026-75689
9.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Summary
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Adobe | Adobe Connect | 0 <= 12.11 | affected |
| Adobe | Adobe Connect | 12.11.1, 12.12 | unaffected |
| Adobe | Adobe Connect Android Mobile App | 0 <= 4.4 | affected |
| Adobe | Adobe Connect Android Mobile App | 4.5 | unaffected |
Weaknesses
- CWE-79: Cross-site Scripting (Stored XSS) (CWE-79)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.