Cross-Site Scripting Vulnerability in Adobe Connect
CVE-2026-34617

8.7HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
14 April 2026

What is CVE-2026-34617?

Adobe Connect versions 2025.3 and 12.10 and earlier are susceptible to a Cross-Site Scripting (XSS) vulnerability that allows low-privileged attackers to inject malicious scripts into web pages. If successfully exploited, this vulnerability could lead to privilege escalation, enabling attackers to gain elevated access to the victim’s account or session. Exploitation necessitates user interaction, as victims must navigate to a specially crafted URL or engage with a compromised webpage, changing the scope of the security risk.

Affected Version(s)

Adobe Connect 0 <= 12.10

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.