Reflected Cross-Site Scripting in Adobe Connect Versions by Adobe
CVE-2026-34614
6.1MEDIUM
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-34614?
Adobe Connect versions 2025.3, 12.10 and earlier are vulnerable to a reflected Cross-Site Scripting (XSS) issue. This vulnerability allows attackers to inject malicious JavaScript content into web pages. If a user is tricked into clicking a specially crafted link, the malicious script can execute in their browser session, potentially leading to unauthorized actions and exposure of sensitive information.
Affected Version(s)
Adobe Connect 0 <= 12.10
Adobe Connect Desktop Application 0 <= 2025.3
Adobe Connect 12.11