---
id: CVE-2026-75682
title: >-
  Adobe Connect is affected by an Improper Neutralization of Special Elements
  used in an SQL Command ('SQL Injection') vulnerability that could result in
  arbitrary code execution in the context of the current user
summary: >-
  Adobe Connect is affected by an Improper Neutralization of Special Elements
  used in an SQL Command ('SQL Injection') vulnerability that could result in
  arbitrary code execution in the context of the current user. A low-privileged
  attacke…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: Adobe
product: Adobe Connect
affected:
  - connect <= 12.11
  - connect_android_mobile_app <= 4.4
published: '2026-09-22'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T13:17:28.433'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75682'
references:
  - url: 'https://helpx.adobe.com/security/products/connect/apsb26-150.html'
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T03:56:10.085100Z'
ingestedAt: '2026-09-22T19:09:09.995Z'
epss: 0.00951
epssPercentile: 0.59802
---

## Overview

Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
