Stored Cross-Site Scripting Vulnerability in Adobe Connect
CVE-2026-48361

6.1MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
22 September 2026

What is CVE-2026-48361?

Adobe Connect is vulnerable to a stored Cross-Site Scripting (XSS) attack, enabling attackers to inject malicious scripts into specific form fields. When users interact with these compromised fields, harmful JavaScript can be executed within their web browsers, leading to potential data compromise or session hijacking. Ensuring proper validation and sanitization of user input is essential to mitigate this risk.

Affected Version(s)

Adobe Connect 0 <= 12.11

Adobe Connect Android Mobile App 0 <= 4.4

Adobe Connect 12.11.1, 12.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.