CVE-2026-75684: Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an authenticated attacker or direct access to the target?
No. The vector indicates network-based exploitation with no privileges required by the attacker. Exploitation does require user interaction: a victim must browse to a page containing the malicious content.
What is the likely impact if a victim triggers the malicious script?
The injected JavaScript can execute in the victim's browser and may allow elevated access to or control over the victim's account or session. The vulnerability is rated as having high confidentiality and integrity impact, with no availability impact indicated.
Are only the attacker and victim affected, or can the impact cross a security boundary?
The CVSS vector indicates changed scope, meaning the impact may extend beyond the vulnerable component's original security authority. This is consistent with malicious script execution in a victim's browser session.