CVE-2026-48334

Summary

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Affected Software

VendorProductVersion RangeStatus
AdobeIllustrator Desktop 20260 <= 30.5affected
AdobeIllustrator Desktop 202630.6unaffected
AdobeIllustrator Desktop 20250 <= 29.8.7affected
AdobeIllustrator Desktop 202529.8.9unaffected

Weaknesses

  • CWE-20: Improper Input Validation (CWE-20)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References