CVE-2026-21333

Summary

Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected Software

VendorProductVersion RangeStatus
AdobeIllustrator Desktop 20260 <= 30.1affected
AdobeIllustrator Desktop 202630.2unaffected
AdobeIllustrator Desktop 20250 <= 29.8.4affected
AdobeIllustrator Desktop 202529.8.5unaffected

Weaknesses

  • CWE-426: Untrusted Search Path (CWE-426)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References