
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48395 is an Untrusted Search Path vulnerability (CWE-426) in Adobe Bridge that could result in arbitrary code execution in the context of the current user. The vulnerability affects Adobe Bridge versions 16.0.5 and earlier (fixed in 16.0.6) and versions 15.1.6 and earlier (fixed in 15.1.7). It was disclosed on July 28, 2026, with a CVSS v3.1 base score of 8.6 (High), assigned by Adobe Systems Incorporated (GitHub Advisory, Adobe Advisory).
The vulnerability is classified as CWE-426 (Untrusted Search Path), where Adobe Bridge searches for critical resources using an externally-supplied or attacker-influenced search path that can point to resources outside the application's direct control. This maps to CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) and MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable). Exploitation requires a victim to open a malicious file (user interaction required), and no authentication or elevated privileges are needed on the part of the attacker. The scope is marked as "Changed," indicating that successful exploitation can impact components beyond the vulnerable application itself (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an unauthenticated local attacker to execute arbitrary code with the privileges of the current user by tricking them into opening a malicious file. The impact spans all three security pillars — confidentiality, integrity, and availability are all rated High — and the changed scope indicates potential for impact beyond the Bridge application itself, such as affecting other components or resources accessible to the user. This could enable data theft, installation of malware, or further lateral movement within the user's environment (GitHub Advisory, Adobe Advisory).
cmd.exe, powershell.exe, curl, or other shells/utilities not normally associated with Bridge).Adobe has released patched versions of Adobe Bridge: 16.0.6 (for the 16.x branch) and 15.1.7 (for the 15.x branch). Users should update to these versions immediately via the Creative Cloud desktop application or Adobe's official download channels. As a workaround, users should avoid opening Bridge files received from untrusted or unknown sources, and administrators can implement application execution policies (e.g., Windows Defender Application Control or Software Restriction Policies) to limit DLL loading from untrusted directories (Adobe Advisory, GitHub Advisory).
The CIS (Center for Internet Security) published an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). AusCERT also issued a bulletin (ESB-2026.8732) covering the Adobe Bridge vulnerabilities. Community reaction has been limited, consistent with the absence of public exploits or active exploitation at the time of disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."