{"id":"CVE-2025-54196","title":"Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability","summary":"Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites.  Exploitation of this iss…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","cwe":["CWE-601"],"vendor":"adobe","product":"connect","affected":["connect < 12.10"],"patched":["connect 12.10"],"published":"2025-10-14","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-54196","references":[{"url":"https://helpx.adobe.com/security/products/connect/apsb25-70.html","label":"psirt@adobe.com"}],"tags":["nvd"],"epss":0.00285,"epssPercentile":0.18937,"ingestedAt":"2026-09-30T23:29:32.430Z","slug":"CVE-2025-54196","body":"## Overview\n\nAdobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites.  Exploitation of this issue requires user interaction in that a victim must click on a crafted link.\n\n## Affected\n\n- `connect < 12.10`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `connect 12.10`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}