Executive brief
Adobe Premiere Pro, a professional video editing application, is affected by a security vulnerability that allows for unauthorized file modifications. An attacker could exploit this flaw to bypass built-in security protections and gain unauthorized write access to the system. While the attack does not require user interaction, it depends on specific system conditions beyond the attacker's direct control.
Technical details
An Improper Input Validation vulnerability (CWE-20) exists in Adobe Premiere Pro versions 25.6.5, 26.2.2, and earlier. The flaw allows a local attacker to bypass security features and achieve unauthorized write access to the filesystem. The attack vector is local, requires no user interaction, and results in a scope change (S:C), though successful exploitation depends on specific environmental conditions (AC:H). Adobe has addressed this in versions 25.6.6 and 26.3.
Affected products
- Adobe Premiere Pro <= 25.6.5, <= 26.2.2
Timeline
- 2026-07-14: advisory
- 2026-07-14: disclosed