
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48396 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Bridge that can result in arbitrary code execution in the context of the current user. The vulnerability affects Adobe Bridge versions prior to 15.1.7 (in the 15.x branch) and prior to 16.0.6 (in the 16.x branch). It was published on July 28, 2026, with a patch made available the same day via Adobe's security advisory APSB26-89. The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, Adobe Advisory).
The root cause is an Incorrect Authorization flaw (CWE-863), where Adobe Bridge fails to correctly perform authorization checks when processing certain file types, allowing security boundaries to be bypassed. The attack vector is local, requiring low attack complexity and no privileges, but does require user interaction — specifically, a victim must open a malicious file crafted by the attacker. The changed scope indicator in the CVSS score suggests that successful exploitation can impact resources beyond the vulnerable component itself, potentially affecting other system components or security contexts (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, with high impact to confidentiality, integrity, and availability. The changed scope means the impact can extend beyond Adobe Bridge itself to other system resources or security domains accessible to the user. An attacker who tricks a victim into opening a malicious file could gain full control over the affected user's session, potentially enabling data theft, persistence mechanisms, or lateral movement within the environment (GitHub Advisory, Adobe Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable due to the required user interaction. The EPSS score is approximately 0.16%, placing it in the 6th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
%APPDATA%, %TEMP%, or user home directories) following the opening of an untrusted file in Adobe Bridge; new or modified startup entries or scheduled tasks created by the Bridge process.cmd.exe, powershell.exe, bash, curl, wget); unexpected network connections initiated by the Bridge process.Adobe has released patched versions addressing this vulnerability: Adobe Bridge 15.1.7 (for the 15.x branch) and Adobe Bridge 16.0.6 (for the 16.x branch). Users should update to these versions immediately via the Creative Cloud desktop application or Adobe's official download channels. As a precautionary measure, users should avoid opening Bridge files received from untrusted or unknown sources, and organizations should consider implementing application whitelisting and file execution policies to reduce exposure (Adobe Advisory, GitHub Advisory).
The vulnerability was covered alongside other Adobe security issues patched in the same release cycle, including a higher-profile CVSS 10.0 flaw in Adobe Campaign Classic, which drew more significant media attention (The Hacker News, The Daily Tech Feed). The CIS issued an advisory noting multiple vulnerabilities in Adobe products could allow for arbitrary code execution (CIS Advisory). Community reaction was relatively muted given the lack of active exploitation and the availability of patches at the time of disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."