CVE-2026-34632
HIGHPhotoshop Installer | CWE-427: Uncontrolled Search Path Element
Title source: cnaDescription
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.
References (2)
Core 2
Core References
Third Party Advisory
https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2274
Scores
CVSS v3
8.6
EPSS
0.0027
EPSS Percentile
19.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-427
Status
published
Products (3)
Adobe/Adobe Photoshop Installer
adobe/photoshop_installer
2.11.0.30
adobe/photoshop_set-up.exe
2.11.0.30
Published
Apr 15, 2026
Tracked Since
Apr 16, 2026