Adobe Connect
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Adobe Connect.
Recent Adobe Connect Security Advisories
| Advisory | Title | Published |
|---|---|---|
| APSB26-150 | Security updates available for Adobe Connect | APSB26-150 | September 22, 2026 |
| APSB26-50 | Security updates available for Adobe Connect | APSB26-50 | May 12, 2026 |
| APSB26-37 | Security updates available for Adobe Connect | APSB2 APSB26-37 | April 14, 2026 |
| APSB25-70 | Security updates available for Adobe Connect | APSB25-70 | October 14, 2025 |
| APSB25-61 | Security updates available for Adobe Connect | APSB25-61 | July 8, 2025 |
| APSB25-36 | Security updates available for Adobe Connect | APSB25-36 | May 13, 2025 |
| APSB24-99 | Security updates available for Adobe Connect | APSB24-99 | December 10, 2024 |
| APSB23-33 | Security updates available for Adobe Connect | APSB23-33 | September 12, 2023 |
| APSB23-05 | Security updates available for Adobe Connect | APSB23-05 | February 14, 2023 |
| APSB21-112 | Security update available for Adobe Connect APSB21-112 | December 14, 2021 |
By the Year
In 2026 there have been 20 vulnerabilities in Adobe Connect with an average score of 8.7 out of ten. Last year, in 2025 Connect had 8 security vulnerabilities published. That is, 12 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.42.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 20 | 8.70 |
| 2025 | 8 | 7.28 |
| 2024 | 19 | 6.51 |
| 2023 | 3 | 5.83 |
| 2022 | 0 | 0.00 |
| 2021 | 9 | 6.42 |
| 2020 | 2 | 6.10 |
| 2019 | 1 | 5.30 |
| 2018 | 5 | 9.03 |
It may take a day or so for new Connect vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Adobe Connect Security Vulnerabilities
Adobe Connect Stored XSS via Form Fields
CVE-2026-75689
9.3 - Critical
- September 22, 2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
XSS
Adobe Connect Improper Cert Validation leads to memory disclosure
CVE-2026-83964
6.2 - Medium
- September 22, 2026
Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.
Improper Certificate Validation
Adobe Connect Path Traversal (CVE-2026-34689) Enables Arbitrary File Read
CVE-2026-34689
8.6 - High
- September 22, 2026
Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Directory traversal
Adobe Connect Improper Input Validation Arbitrary Code Execution
CVE-2026-75686
9.3 - Critical
- September 22, 2026
Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Improper Input Validation
Adobe Connect SQL Injection (CVE-2026-75682)
CVE-2026-75682
9.9 - Critical
- September 22, 2026
Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.
SQL Injection
Adobe Connect Reflected XSS in URL Enables Session Escape
CVE-2026-75698
9.3 - Critical
- September 22, 2026
Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
XSS
Adobe Connect Stored XSS via Form Fields
CVE-2026-48361
6.1 - Medium
- September 22, 2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
XSS
Adobe Connect Stored XSS in Form Fields
CVE-2026-75684
9.3 - Critical
- September 22, 2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
XSS
Adobe Connect Stored XSS in Form Fields
CVE-2026-75697
9.3 - Critical
- September 22, 2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
XSS
Adobe Campaign Classic: Incorrect Auth Allows Arbitrary Code Exec
CVE-2026-27302
10 - Critical
- August 11, 2026
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
AuthZ
Adobe Connect <2025.9.15: Deserialization Untrusted Data -> Arbitrary Code Exec
CVE-2026-34659
9.6 - Critical
- May 12, 2026
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Marshaling, Unmarshaling
Adobe Connect <2025.9.15 Incorrect Auth Allows Arbitrary Code Exec
CVE-2026-34660
9.3 - Critical
- May 12, 2026
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
AuthZ
Adobe Connect XSS before 2025.3 Privilege Escalation
CVE-2026-34617
8.7 - High
- April 14, 2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
XSS
Adobe Connect 12.10, 2025.3 Deser: Untrusted Data Arbitrary Code Exec
CVE-2026-27303
9.6 - Critical
- April 14, 2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Marshaling, Unmarshaling
Adobe Connect 2025.3/12.10 and below: Reflected XSS (CVE-2026-21331)
CVE-2026-21331
6.1 - Medium
- April 14, 2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
XSS
Adobe Connect 2025.3/12.10 DOM-based XSS Vulnerability (CVE-2026-27246)
CVE-2026-27246
9.3 - Critical
- April 14, 2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
XSS
Adobe Connect Reflected XSS before 12.10, Scope Changed
CVE-2026-34614
6.1 - Medium
- April 14, 2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
XSS
Adobe Connect 2025.3 & 12.10: Reflected XSS (CVE-2026-27245)
CVE-2026-27245
9.3 - Critical
- April 14, 2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
XSS
Adobe Connect 12.10/2025.3 Deserialization Exploit
CVE-2026-34615
9.3 - Critical
- April 14, 2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Marshaling, Unmarshaling
Adobe Connect 12.10 Reflected XSS via URL, Scope Change
CVE-2026-27243
9.3 - Critical
- April 14, 2026
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
XSS
Adobe Connect 12.9- Dom XSS in Web UI (CVE-2025-49552)
CVE-2025-49552
8.1 - High
- October 14, 2025
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Scope is changed.
XSS
Adobe Connect <=12.9 DOM XSS via crafted page
CVE-2025-49553
9.3 - Critical
- October 14, 2025
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Scope is changed.
XSS
Adobe Connect <=12.9 OpenRedirect Vulnerability
CVE-2025-54196
4.3 - Medium
- October 14, 2025
Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link.
Open Redirect
Adobe Connect 24.0 and earlier: Deserialization of Untrusted Data causing RCE
CVE-2025-27203
9.6 - Critical
- July 08, 2025
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is changed.
Marshaling, Unmarshaling
Adobe Connect <=12.8 Stored XSS via Form Fields
CVE-2025-30316
5.4 - Medium
- May 13, 2025
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field.
XSS
Adobe Connect 12.8 and earlier – Stored XSS in form fields
CVE-2025-30315
6.1 - Medium
- May 13, 2025
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field.
XSS
Adobe Connect 12.8-: Stored XSS in Form Fields
CVE-2025-30314
6.1 - Medium
- May 13, 2025
Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field.
XSS
Adobe Connect 12.8- XSS in Form Fields
CVE-2025-43567
9.3 - Critical
- May 13, 2025
Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
XSS
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-54048
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-54049
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect URL Redirection Vulnerability
CVE-2024-54050
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
Open Redirect
Adobe Connect URL Redirection Vulnerability
CVE-2024-54051
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
Open Redirect
Adobe Connect Improper Access Control Vulnerability
CVE-2024-54038
4.3 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.
Authorization
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-54047
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-54046
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-54045
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-54044
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-54043
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-54042
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an unauthenticated attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect Stored XSS Vulnerability in Form Fields
CVE-2024-54041
5.4 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field.
XSS
Adobe Connect Stored XSS Vulnerability in Form Fields
CVE-2024-54040
5.4 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field.
XSS
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-49550
6.1 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect Stored XSS Vulnerability in Form Fields
CVE-2024-54039
5.4 - Medium
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field.
XSS
Adobe Connect DOM-based XSS Vulnerability
CVE-2024-54037
8.1 - High
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the high-privileged attacker can inject malicious scripts that run when the page is rendered. This type of attack requires user interaction, as the victim would need to visit a malicious link or input data into a compromised form. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
XSS
Adobe Connect Stored XSS Vulnerability in Form Fields
CVE-2024-54036
9.3 - Critical
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
XSS
Adobe Connect Reflected Cross-Site Scripting (XSS) Vulnerability
CVE-2024-54034
9.3 - Critical
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
XSS
Adobe Connect Stored XSS Vulnerability in Form Fields
CVE-2024-54032
9.3 - Critical
- December 10, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victims browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
XSS
Adobe Connect 12.3 Reflected XSS on Vulnerable Page
CVE-2023-29305
6.1 - Medium
- September 13, 2023
Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect 12.3- Reflected XSS Vulnerability (CVE-2023-29306)
CVE-2023-29306
6.1 - Medium
- September 13, 2023
Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
XSS
Adobe Connect Improper Access Control (v11.4.5-, v12.1.5-): Feature Bypass
CVE-2023-22232
5.3 - Medium
- February 17, 2023
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.
Authorization
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Adobe Connect or by Adobe? Click the Watch button to subscribe.