Junglewise Threat Intelligence

CVE-2026-48345: Adobe Animate OS command injection via malicious file

CVE-2026-48345 · Severity: high · CVSS 8.2 · Published 2026-07-14

Executive brief

Adobe Animate, a professional animation and multimedia authoring tool, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands and access or delete sensitive data with the same permissions as the logged-in user.

Technical details

An OS Command Injection vulnerability (CWE-78) exists in Adobe Animate due to improper neutralization of special elements used in operating system commands. The vulnerability is triggered when the application processes a maliciously crafted file, requiring user interaction (UI:R). Successful exploitation allows for arbitrary code execution in the context of the current user, with a changed scope (S:C) indicating potential impact beyond the application itself. Adobe has addressed this in versions 23.0.16 and 24.0.14.

Affected products

  • Adobe Animate 2023 <= 23.0.15
  • Adobe Animate 2024 <= 24.0.13

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats