Junglewise Threat Intelligence

CVE-2026-48344: Adobe Creative Cloud Desktop TOCTOU race condition

CVE-2026-48344 · Severity: high · CVSS 7.8 · Published 2026-07-14

Vendors: Adobe.

Executive brief

Adobe Creative Cloud Desktop, the management application for Adobe's suite of creative software, is affected by a security flaw that could allow an attacker to run unauthorized commands on a computer. If exploited, this could lead to a full system compromise or unauthorized access to user data. The attack requires the attacker to already have limited access to the machine and relies on specific timing conditions to succeed.

Technical details

A Time-of-check Time-of-use (TOCTOU) race condition (CWE-367) exists in Adobe Creative Cloud Desktop versions 6.9.1.1 and earlier. An attacker with local low-privileged access can exploit a timing window between the application's validation of a resource and its subsequent use. Successful exploitation allows for arbitrary code execution with the privileges of the current user, and because the scope is changed (S:C), it may allow for escalation or impact beyond the immediate application environment. No user interaction is required, though the attack complexity is high due to the precise timing required for a successful race condition. The issue is resolved in version 6.10.0.252.3.

Affected products

  • Adobe Creative Cloud Desktop <= 6.9.1.1

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats