Executive brief
Adobe Bridge, a creative asset management tool, is affected by a security flaw that could allow an attacker to gain elevated permissions on a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could gain unauthorized access to read or modify sensitive data, potentially compromising the integrity of the user's workstation.
Technical details
An Incorrect Authorization vulnerability (CWE-863) exists in Adobe Bridge versions 15.1.6, 16.0.5, and earlier. The flaw allows for privilege escalation and unauthorized read/write access when a victim is enticed into opening a malicious file. The attack vector is local, but the vulnerability is notable for having a 'Changed' scope (S:C) in its CVSS metric, indicating it may impact components beyond the Adobe Bridge application itself. Adobe has addressed this issue in versions 15.1.7 and 16.0.6.
Affected products
- Adobe Bridge <= 15.1.6, <= 16.0.5
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory