CVE-2026-48361: Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to do to exploit this issue?
The attacker needs to inject malicious script into a vulnerable form field and cause a victim to browse to the page containing that field. The vulnerability is network-reachable and does not require attacker privileges, but victim interaction is required.
Who is at risk from a successful exploit?
Users who browse to a page containing an attacker-controlled value in a vulnerable form field may execute the malicious JavaScript in their browser. The changed scope indicates the impact can extend beyond the vulnerable component's own security authority.