Untrusted Search Path Vulnerability in Adobe Illustrator
CVE-2026-21333

8.6HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
10 March 2026

What is CVE-2026-21333?

Adobe Illustrator versions 29.8.4, 30.1, and earlier are vulnerable to an untrusted search path issue. This vulnerability allows attackers to potentially execute arbitrary code within the context of the user when a malicious file is opened. User interaction is necessary for the exploitation to occur, making it crucial for users to be cautious with files from untrusted sources.

Affected Version(s)

Illustrator 0 <= 30.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.