LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-34617

CVE-2026-34617 - Vulnerability Analysis

HighCVSS: 8.7

Last Updated: April 14, 2026

Adobe Connect - Stored XSS & Privilege Escalation

Published: April 14, 2026Updated: April 14, 2026Remote Exploitable

Overview

Adobe Connect <= 2025.3, 12.10 contains a stored XSS caused by improper input sanitization, letting low-privileged attackers inject scripts and escalate privileges, exploit requires victim interaction with crafted URL or page.

Severity & Score

Severity: High
CVSS Score: 8.7

Impact

Low-privileged attackers can escalate privileges by injecting malicious scripts, potentially gaining control over victim accounts or sessions.

Mitigation

Update to the latest version beyond 2025.3 or 12.10.

Details

CVE ID
CVE-2026-34617
Severity
High
CVSS Score
8.7
Type
stored_xss
Status
new

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N