Cyber & AI intelligence
Wasteland.
Briefs indexed2842
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-75682 2026-09-22

CVE-2026-75682: Critical SQL Injection in Adobe Connect Enables Arbitrary Code Execution

"Adobe has disclosed a critical (CVSS 9.9) SQL injection flaw in Adobe Connect that, according to Adobe's advisory, lets an attacker holding low-level privileges execute arbitrary SQL commands without any user…"

Adobe has disclosed a critical (CVSS 9.9) SQL injection flaw in Adobe Connect that, according to Adobe's advisory, lets an attacker holding low-level privileges execute arbitrary SQL commands without any user interaction, potentially escalating control over a victim's account or session.

What Is It

CVE-2026-75682 is an Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) in Adobe Connect. Per Adobe's PSIRT advisory, the flaw can result in arbitrary code execution in the context of the current user. A low-privileged attacker can exploit it to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session.

Exploitation does not require user interaction, and the CVSS scope is marked as changed; meaning successful exploitation can impact resources beyond the vulnerable component's own security scope.

Why It Matters

The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The combination is close to worst-case: network attack vector, low attack complexity, only low privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability.

In practical terms, the scoring implies that an account with only low-level privileges on a Connect deployment could become a path to significant compromise of data and session control. Adobe's advisory does not detail the specific privilege level or attack path required, but the changed-scope rating suggests impact reaching past the vulnerable component itself. There is no user-interaction dependency to slow an attacker down.

What's Vulnerable

Adobe lists two affected products:

No CPE match data is currently published in the NVD record.

Patch Status

Fixed builds are available. Administrators should move Adobe Connect servers to 12.11.1 or 12.12, and Android mobile clients to 4.5, per Adobe Security Bulletin APSB26-150.

The NVD record was published 2026-09-22 and remains in Awaiting Analysis status, so NVD-assigned metrics and configuration data may change. The CVSS score above is Adobe's own (source: [email protected]).

As of publication, CVE-2026-75682 is not listed in the CISA Known Exploited Vulnerabilities catalog, and Adobe's advisory does not indicate awareness of exploitation in the wild.

Sources