Junglewise Threat Intelligence

CVE-2026-48348: Adobe Animate incorrect authorization code execution

CVE-2026-48348 · Severity: high · CVSS 7.7 · Published 2026-07-14

Executive brief

Adobe Animate, a popular multimedia authoring and computer animation program, is affected by a security vulnerability that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could execute unauthorized commands or software with the same permissions as the logged-in user, potentially leading to data theft or full system compromise.

Technical details

An Incorrect Authorization vulnerability (CWE-863) exists in Adobe Animate versions 23.0.15 and 24.0.13 and earlier. The flaw is triggered when the application improperly validates permissions or authorizations, which can be leveraged to achieve arbitrary code execution. The attack vector is local and requires user interaction, specifically requiring a victim to open a maliciously crafted file. While the complexity is rated as high due to conditions beyond the attacker's immediate control, a successful exploit results in a scope change, allowing the attacker to execute code in the context of the current user. Adobe has released patches in versions 23.0.16 and 24.0.14 to address this issue.

Affected products

  • Adobe Animate 2023 <= 23.0.15
  • Adobe Animate 2024 <= 24.0.13

Timeline

  • 2026-07-14: advisory: Adobe published security bulletin APSB26-83
  • 2026-07-14: disclosed

References

Related threats