Description
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Published: 2026-09-22
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Patch immediately
AI Analysis

Impact

A stored Cross‑Site Scripting vulnerability allows an attacker to inject malicious JavaScript into vulnerable form fields within Adobe Connect. When a user visits a page containing the stored payload, the script executes in the victim’s browser context, potentially enabling the attacker to hijack the user’s session or gain elevated control over the account. The flaw also changes the affected system’s security scope, indicating broader vulnerability reach.

Affected Systems

Adobe Connect for web clients and the Adobe Connect Android Mobile App are impacted. The vulnerability affects all installations that allow users to create or edit form fields stored by the application, regardless of operating system.

Risk and Exploitability

The CVSS score of 9.3 highlights a critical impact. Because the vulnerability can elevate an attacker’s privileges within the application, it demands immediate attention. While the EPSS score is not available, the high CVSS indicates that an attacker with the ability to inject content can cause substantial damage. The vulnerability is not catalogued in KEV, but a lack of public exploitation does not lessen the risk posed by a high‑score stored XSS flaw. The likely attack vector is through manipulation of form fields that persist user input across sessions, and the vulnerability is inferred to be exploitable by those with write access to those fields.

Generated by OpenCVE AI on September 22, 2026 at 21:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Connect security patch that addresses the stored XSS flaw
  • Implement strict input validation and output encoding on all form fields to prevent script injection
  • Restrict form creation and editing privileges to trusted users only and enforce least privilege policies

Generated by OpenCVE AI on September 22, 2026 at 21:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Title Adobe Connect | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T19:22:05.490Z

Reserved: 2026-08-18T01:29:54.619Z

Link: CVE-2026-75697

cve-icon Vulnrichment

Updated: 2026-09-22T19:21:54.279Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:46.770

Modified: 2026-09-22T20:17:06.173

Link: CVE-2026-75697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:15:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')