CVE-2026-48391

HIGH

Adobe Bridge - Bridge | Untrusted Search Path (CWE-426)

Title source: rule
STIX 2.1

Description

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

References (1)

Core 1
Core References

Scores

CVSS v3 8.2
EPSS 0.0015
EPSS Percentile 5.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426
Status published
Products (4)
Adobe/Adobe Bridge < 15.1.6
Adobe/Adobe Bridge < 16.0.5
Adobe/Adobe Bridge 15.1.7
Adobe/Adobe Bridge 16.0.6
Published Jul 28, 2026
Tracked Since Jul 29, 2026