Executive brief
Adobe Animate, a professional animation and multimedia authoring tool, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could execute unauthorized commands or software with the same permissions as the logged-in user, potentially leading to data theft or further system compromise.
Technical details
Adobe Animate is vulnerable to an Untrusted Search Path (CWE-426) flaw. The vulnerability occurs when the application attempts to load a resource or library without specifying a fully qualified path, potentially allowing a local attacker to place a malicious file in a directory searched by the application. Exploitation requires a user to open a malicious file, leading to arbitrary code execution in the context of the current user. Adobe has addressed this in Animate 2023 version 23.0.16 and Animate 2024 version 24.0.14.
Affected products
- Adobe Animate 2023 <= 23.0.15
- Adobe Animate 2024 <= 24.0.13
Timeline
- 2026-07-14: advisory: Adobe published security bulletin APSB26-83
- 2026-07-14: disclosed: CVE-2026-48346 published to NVD