Untrusted Search Path Vulnerability in Adobe Bridge
CVE-2026-48395

8.6HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
28 July 2026

What is CVE-2026-48395?

Adobe Bridge is susceptible to an Untrusted Search Path vulnerability that can lead to arbitrary code execution with user interaction. For successful exploitation, an attacker must entice a victim into opening a malicious file, which then allows the execution of harmful code within the current user context. This security flaw changes the trust level of file execution paths, creating risks for users of the affected versions.

Affected Version(s)

Adobe Bridge 0 <= 16.0.5

Adobe Bridge 0 <= 15.1.6

Adobe Bridge 16.0.6

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.