Server-Side Request Forgery Vulnerability in Premiere Pro from Adobe
CVE-2026-84395

7.1HIGH

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-84395?

Adobe Premiere Pro is impacted by a Server-Side Request Forgery vulnerability that allows an attacker to manipulate requests sent from the server, potentially leading to privilege escalation. This vulnerability does not require user interaction to exploit, making it a serious concern for users. It is crucial for organizations utilizing Premiere Pro to evaluate their environments and mitigate risks associated with this flaw.

Affected Version(s)

Premiere 0 <= 26.3.2

Premiere 0 <= 25.6.5

Premiere 26.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.