CVE-2026-48391

Summary

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Affected Software

VendorProductVersion RangeStatus
AdobeAdobe Bridge0 <= 16.0.5affected
AdobeAdobe Bridge16.0.6unaffected
AdobeAdobe Bridge0 <= 15.1.6affected
AdobeAdobe Bridge15.1.7unaffected

Weaknesses

  • CWE-426: Untrusted Search Path (CWE-426)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References