PT-2026-96983 · Adobe · Connect
CVE-2026-75682
·
Published
2026-09-22
·
Updated
2026-09-25
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adobe Connect versions prior to 12.12
Description
Adobe Connect contains an SQL Injection flaw, which occurs when special elements used in an SQL command are not properly neutralized. This allows a low-privileged attacker to execute arbitrary SQL commands without requiring user interaction, potentially leading to arbitrary code execution in the context of the current user and unauthorized elevation of access or control over accounts and sessions. Approximately 23.7k instances are identified globally.
Recommendations
Update Adobe Connect to version 12.12.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connect