Adobe has disclosed a critical (CVSS 9.9) SQL injection flaw in Adobe Connect that, according to Adobe's advisory, lets an attacker holding low-level privileges execute arbitrary SQL commands without any user interaction, potentially escalating control over a victim's account or session.
What Is It
CVE-2026-75682 is an Improper Neutralization of Special Elements used in an SQL Command vulnerability (CWE-89) in Adobe Connect. Per Adobe's PSIRT advisory, the flaw can result in arbitrary code execution in the context of the current user. A low-privileged attacker can exploit it to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session.
Exploitation does not require user interaction, and the CVSS scope is marked as changed; meaning successful exploitation can impact resources beyond the vulnerable component's own security scope.
Why It Matters
The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The combination is close to worst-case: network attack vector, low attack complexity, only low privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability.
In practical terms, the scoring implies that an account with only low-level privileges on a Connect deployment could become a path to significant compromise of data and session control. Adobe's advisory does not detail the specific privilege level or attack path required, but the changed-scope rating suggests impact reaching past the vulnerable component itself. There is no user-interaction dependency to slow an attacker down.
What's Vulnerable
Adobe lists two affected products:
- Adobe Connect: versions up to and including 12.11 are affected. Versions 12.11.1 and 12.12 are unaffected.
- Adobe Connect Android Mobile App: versions up to and including 4.4 are affected. Version 4.5 is unaffected.
No CPE match data is currently published in the NVD record.
Patch Status
Fixed builds are available. Administrators should move Adobe Connect servers to 12.11.1 or 12.12, and Android mobile clients to 4.5, per Adobe Security Bulletin APSB26-150.
The NVD record was published 2026-09-22 and remains in Awaiting Analysis status, so NVD-assigned metrics and configuration data may change. The CVSS score above is Adobe's own (source: [email protected]).
As of publication, CVE-2026-75682 is not listed in the CISA Known Exploited Vulnerabilities catalog, and Adobe's advisory does not indicate awareness of exploitation in the wild.
Sources
- Adobe Security Bulletin APSB26-150; https://helpx.adobe.com/security/products/connect/apsb26-150.html
- NVD, CVE-2026-75682, https://nvd.nist.gov/vuln/detail/CVE-2026-75682
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog