
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48395 is an Untrusted Search Path vulnerability (CWE-426) in Adobe Bridge that can result in arbitrary code execution in the context of the current user. It affects Adobe Bridge versions prior to 15.1.7 (in the 15.x line) and prior to 16.0.6 (in the 16.x line). The vulnerability was published on July 28, 2026, with a patch advisory released by Adobe on August 3, 2026. It carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, Adobe Advisory).
The vulnerability is classified as CWE-426 (Untrusted Search Path), meaning Adobe Bridge searches for critical resources using an externally-supplied or attacker-influenced search path that can point to resources outside the application's direct control. This maps to MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths). Exploitation requires a victim to open a malicious file, at which point Bridge resolves a resource via an untrusted path, allowing an attacker-controlled library or executable to be loaded and run. The scope is marked as "Changed," indicating the impact can extend beyond the Bridge process itself (GitHub Advisory, Adobe Advisory).
Successful exploitation results in arbitrary code execution with the privileges of the current user, with high impact to confidentiality, integrity, and availability. Because the scope is changed, the attacker's code may affect resources or components beyond the Bridge application itself, potentially enabling lateral movement or privilege escalation depending on the user's environment. Sensitive files accessible to the victim user are at risk of exfiltration or modification (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting. The EPSS score is approximately 0.169% (7th percentile), indicating a low near-term probability of exploitation. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, as it requires user interaction (opening a malicious file). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Adobe Advisory).
cmd.exe, powershell.exe, curl, or other shells/utilities not normally associated with Bridge).Adobe has released patched versions: Bridge 15.1.7 (for the 15.x line) and Bridge 16.0.6 (for the 16.x line). Users should update to these versions immediately via the Adobe Creative Cloud desktop application or Adobe's official download channels. As interim mitigations, users should avoid opening Bridge files from untrusted or unknown sources, and administrators should consider implementing application execution policies (e.g., Windows Defender Application Control or AppLocker) to restrict DLL loading from user-writable directories (Adobe Advisory, GitHub Advisory).
The vulnerability received coverage as part of broader reporting on Adobe's July/August 2026 patch cycle, which also included a higher-profile CVSS 10.0 flaw in Adobe Campaign Classic. Coverage from The Hacker News, Security Affairs, and Heise focused primarily on the Campaign Classic vulnerability, with Bridge's CVE-2026-48395 mentioned in the context of Adobe's broader patch release. The CIS issued an advisory noting multiple vulnerabilities in Adobe products could allow arbitrary code execution (CIS Advisory). Community sentiment on social media was relatively muted for this specific CVE given the absence of public exploits.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."