CVE-2026-76191

Summary

Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Affected Software

VendorProductVersion RangeStatus
AdobeAdobe Animate 20230 <= 23.0.16affected
AdobeAdobe Animate 202323.0.17unaffected
AdobeAdobe Animate 20240 <= 24.0.14affected
AdobeAdobe Animate 202424.0.15unaffected

Weaknesses

  • CWE-94: Improper Control of Generation of Code ('Code Injection') (CWE-94)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References