Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
8.6
CVE-2026-34689PATCHED
adobe · adobe connect

Adobe Connect | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

Description

Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

Affected Products

VendorProductVersions
adobeadobe connect0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
adobeconnectcert_advisory90%

References

  • https://helpx.adobe.com/security/products/connect/apsb26-150.html(vendor-advisory)

Related News (2 articles)

Tier B
BSI Advisories4d ago
[NEU] [hoch] Adobe Connect: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-34689 | Adobe Connect/Connect Android Mobile App path traversal
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
12.11.112.124.5
CWECWE-22
PublishedSep 22, 2026
Trending Score28
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71362EXPKEV
Adobe Commerce | Incorrect Authorization (CWE-863)
Trending: 109
CRITICALCVE-2026-75745
Adobe Experience Manager Forms JEE | Incorrect Authorization (CWE-863)
Trending: 36
CRITICALCVE-2026-75682
Adobe Connect | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Trending: 29
CRITICALCVE-2026-82000
Adobe Experience Manager Forms JEE | Server-Side Request Forgery (SSRF) (CWE-918)
Trending: 29
CRITICALCVE-2026-75698
Adobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)
Trending: 29

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 22, 2026
Discovered by ZDM
Sep 22, 2026
Patch Available
Sep 24, 2026