Executive brief
Adobe Animate, a professional multimedia authoring and computer animation program, is affected by a security flaw that could allow an attacker to run unauthorized commands on a user's computer. If exploited, this could lead to a full system compromise, allowing an attacker to access sensitive files or disrupt operations. While the attack does not require the user to take any action, it does rely on specific system conditions that are outside of the attacker's direct control.
Technical details
Adobe Animate contains an incorrect authorization vulnerability (CWE-863) that can lead to arbitrary code execution. The flaw exists in how the application validates permissions or access controls, allowing an attacker to execute code with the privileges of the logged-in user. The attack vector is local, and while it does not require user interaction (UI:N) or prior privileges (PR:N), it has high attack complexity (AC:H) because successful exploitation depends on conditions beyond the attacker's immediate control. The vulnerability also results in a scope change (S:C), indicating it may impact components beyond the Animate application itself. Patches are available in versions 23.0.16 and 24.0.14.
Affected products
- Adobe Animate 2023 <= 23.0.15
- Adobe Animate 2024 <= 24.0.13
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory