Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
The vulnerability results from improper input handling in the DOM (Document Object Model) model of the Adobe Connect application, which enables embedding malicious JavaScript code directly into the page structure on the client side. An attacker must trick the victim into visiting a specially crafted URL or interacting with an infected website. On the victim's side, the malicious script is executed in their browser in the context of a trusted application session. The scope change indicates that the effects of script execution may extend beyond the original application.
An attacker can obtain elevated access to the victim's account or session, and through an injected script — steal authentication credentials, session tokens, or perform unauthorized actions on behalf of the logged-in user.
Adobe Connect should be updated to a version newer than 2025.3 / 12.10 in accordance with the manufacturer's recommendations published at: https://helpx.adobe.com/security/products/connect/apsb26-37.html. Until the patch is installed, users should be warned against clicking on unknown links leading to Adobe Connect instances and should consider implementing Content Security Policy (CSP) policies.
Adobe Connect in version 2025.3, 12.10 and earlier, running on Microsoft Windows and Apple macOS platforms (including the Adobe Connect Desktop Application).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NAdobe Connect
APPAdobe< 12.11Adobe Connect Desktop Application
APPAdobe≤ 2025.3< 2025.9.15Apple macOS
OSAppleall versionsMicrosoft Windows
OSMicrosoftall versions
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP