
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75990 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Illustrator that can result in arbitrary code execution in the context of the current user. The vulnerability affects Adobe Illustrator Desktop 2025 (versions up to and including 29.8.10) and Adobe Illustrator Desktop 2026 (versions up to and including 30.7). It was published on September 8, 2026, with a patch made available shortly after. The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, Adobe Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization), meaning Adobe Illustrator fails to correctly perform authorization checks when processing certain file content, allowing unauthorized actions to occur. The attack vector is local — an attacker must deliver a specially crafted malicious file to the victim, who must then open it in Illustrator. No privileges are required on the part of the attacker, but user interaction is mandatory. Notably, the scope is marked as "Changed," indicating that successful exploitation can impact resources beyond the vulnerable component itself (GitHub Advisory, Adobe Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact. Because the scope is changed, the exploitation can affect resources or components beyond the Illustrator application itself, potentially enabling further access to the underlying system. Data exposure, file system manipulation, and persistence mechanisms are all plausible consequences depending on the privileges of the targeted user (GitHub Advisory).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.2%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. Exploitation requires user interaction, which reduces the likelihood of automated or mass exploitation.
.ai, .eps, or other supported format) that exploits the incorrect authorization logic when parsed by Illustrator.%APPDATA%, %TEMP%, or /tmp) shortly after opening an Illustrator file; new or modified startup/persistence entries (registry run keys on Windows, LaunchAgents on macOS).cmd.exe, powershell.exe, bash, curl, wget); unexpected network connections initiated by the Illustrator process.Adobe has released patched versions addressing this vulnerability: Illustrator Desktop 2025 version 29.8.11 and Illustrator Desktop 2026 version 30.8. Users should update to these versions immediately via the Creative Cloud desktop application or Adobe's update mechanism. As a general precaution, users should avoid opening Illustrator files received from untrusted or unknown sources, and organizations may consider implementing application whitelisting or file execution policies to reduce risk (Adobe Advisory, GitHub Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution (CIS Advisory). Tenable published a Nessus detection plugin (ID 343840) for this vulnerability, enabling automated scanning of affected systems. No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability tracking and advisory coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."