
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76199 is an Uncontrolled Search Path Element vulnerability (CWE-427) in Adobe Photoshop Desktop that allows arbitrary code execution in the context of the current user. It affects Photoshop 2025 versions up to and including 26.11.6, and Photoshop 2026 versions up to and including 27.6. The vulnerability was published on September 8, 2026, with patches made available the same day. It carries a CVSS v3.1 base score of 8.6 (High) (GitHub Advisory, Adobe Advisory).
The vulnerability is classified as CWE-427 (Uncontrolled Search Path Element), meaning Photoshop Desktop uses a search path that includes one or more locations controllable by an attacker. Exploitation occurs locally when a victim opens a specially crafted malicious file, triggering Photoshop to load a resource (such as a DLL or dynamic library) from an attacker-controlled path instead of the intended trusted location — a technique consistent with DLL Search Order Hijacking (MITRE ATT&CK T1574.001) or Dylib Hijacking (T1574.004). The attack requires no privileges from the attacker but does require user interaction (opening the malicious file), and the scope is marked as changed, indicating impact can extend beyond the Photoshop process itself (GitHub Advisory, Adobe Advisory).
Successful exploitation results in arbitrary code execution in the context of the current user, with high impact to confidentiality, integrity, and availability. An attacker can read sensitive data accessible to the user, modify or delete files, and disrupt system availability. Because the scope is changed, the impact may extend beyond the Photoshop application boundary to affect other system components or resources (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The NVD SSVC assessment confirms exploitation is currently "none" and the vulnerability is not automatable, as it requires a victim to manually open a malicious file. The EPSS score is approximately 0.211% (12th percentile), indicating a low near-term probability of exploitation. CVE-2026-76199 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
cmd.exe, powershell.exe, bash, curl, or network utilities) shortly after a file is opened.Adobe has released patched versions addressing this vulnerability: Photoshop 2025 version 26.11.7 and Photoshop 2026 version 27.7. Users should update immediately via the Creative Cloud desktop application. As interim mitigations, users should avoid opening Photoshop files from untrusted or unknown sources, and administrators should consider restricting write access to directories in Photoshop's library search path. Monitoring for suspicious Photoshop execution patterns is also recommended (Adobe Advisory, GitHub Advisory).
The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution (CIS Advisory). AusCERT published a bulletin (ESB-2026.10694) covering the Adobe September 2026 patch release. Tenable released Nessus detection plugins (IDs 343848 and 343849) for this vulnerability. Community discussion has been limited, consistent with the low EPSS score and absence of public exploits.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."