CVE-2026-27246: Adobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27246?
CVE-2026-27246 is rated as having a medium severity due to its potential for exploitation through DOM-based XSS.
How do I fix CVE-2026-27246?
To fix CVE-2026-27246, upgrade Adobe Connect to version 2025.4 or later.
What products are affected by CVE-2026-27246?
CVE-2026-27246 affects Adobe Connect versions 2025.3 and earlier versions up to 12.10.
What type of vulnerability is CVE-2026-27246?
CVE-2026-27246 is a DOM-based Cross-Site Scripting (XSS) vulnerability.
Can CVE-2026-27246 be exploited remotely?
Yes, CVE-2026-27246 can be exploited remotely by manipulating the DOM to execute malicious JavaScript.