CVE-2026-34689: Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Can this be exploited remotely without credentials or user interaction?
Yes. The vector is network-based, requires low attack complexity, requires no privileges, and does not require user interaction.
What is the likely impact if exploitation succeeds?
An attacker could read arbitrary files, including sensitive files and directories outside the intended access scope. The reported impact is high confidentiality impact, with no integrity or availability impact indicated.
Is the vulnerability limited to the Adobe Connect process or security authority?
No. The reported scope is changed, indicating the impact may extend beyond the security authority of the vulnerable component.