Incorrect Authorization Vulnerability in Adobe Bridge
CVE-2026-48396

8.6HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
28 July 2026

What is CVE-2026-48396?

Adobe Bridge is susceptible to an Incorrect Authorization vulnerability that enables attackers to execute arbitrary code within the context of the current user’s privileges. This flaw requires user interaction; therefore, the victim must open a specially crafted malicious file to become an attack vector. Once exploited, the scope of the user’s privileges can be altered, leading to potentially severe security risks. Users and administrators are advised to ensure they download files from trusted sources to mitigate the risks associated with this vulnerability.

Affected Version(s)

Adobe Bridge 0 <= 16.0.5

Adobe Bridge 0 <= 15.1.6

Adobe Bridge 16.0.6

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.