Executive brief
Adobe Bridge, a creative asset management tool, is affected by a security flaw that could allow an attacker to read sensitive files on a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. This could lead to the unauthorized exposure of private data or system configuration files.
Technical details
Adobe Bridge contains a path traversal vulnerability (CWE-22) due to improper limitation of a pathname to a restricted directory. The flaw is triggered when the application processes a maliciously crafted file, allowing an attacker to bypass directory restrictions and read arbitrary files from the local file system. The attack vector is local and requires user interaction (UI:R), meaning a victim must manually open the malicious file. Successful exploitation could result in a high impact on confidentiality, integrity, and availability. Adobe has released patches in versions 15.1.7 and 16.0.6 to address this issue.
Affected products
- Adobe Bridge <= 15.1.6, <= 16.0.5
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched