CVE-2026-34689

8.6

Adobe · Adobe Connect

Adobe Connect is vulnerable to path traversal, allowing unauthenticated attackers to perform arbitrary file reads on the affected system.

Executive summary

Adobe Connect is susceptible to an unauthenticated path traversal vulnerability that permits unauthorized access to sensitive system files.

Vulnerability

This is an improper limitation of a pathname to a restricted directory (CWE-22) that allows an unauthenticated, remote attacker to bypass directory restrictions and read arbitrary files from the server's file system.

Business impact

The ability for an unauthenticated attacker to read arbitrary files from the file system poses a severe risk to data confidentiality. With a CVSS score of 8.6, this vulnerability could allow for the exfiltration of configuration files, credentials, or sensitive organizational data, potentially leading to a complete compromise of the underlying application environment.

Remediation

Immediate Action: Update Adobe Connect to version 12.11.1 or 12.12, and update the Adobe Connect Android Mobile App to version 4.5 or later.

Proactive Monitoring: Review web server and application access logs for unusual patterns, such as multiple directory traversal sequences like dot-dot-slash, targeting sensitive system paths.

Compensating Controls: Implement a Web Application Firewall (WAF) to detect and block incoming HTTP requests containing path traversal sequences directed at the Adobe Connect application.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high severity of this vulnerability and the lack of authentication required for exploitation, organizations must prioritize patching their Adobe Connect instances immediately. Failure to address this flaw could lead to significant data exposure, and applying the vendor-supplied updates remains the only definitive method for risk mitigation.

More Adobe CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources