Executive brief
Adobe Bridge, a digital asset management application, is affected by a security vulnerability that could allow an attacker to take control of a user's system. To exploit this, an attacker would need to convince a user to open a specially crafted malicious file. Successful exploitation could lead to the unauthorized execution of commands or software on the victim's computer.
Technical details
Adobe Bridge contains an Untrusted Search Path vulnerability (CWE-426) in versions 15.1.6, 16.0.5, and earlier. The flaw occurs when the application attempts to load a resource or library without a fully qualified path, potentially allowing it to load a malicious file placed in a predictable location. An attacker with low privileges can exploit this by placing a malicious file on the local file system and tricking a user into opening a legitimate file associated with the application. This results in arbitrary code execution with the privileges of the logged-in user. Adobe has released versions 15.1.7 and 16.0.6 to address this issue.
Affected products
- Adobe Bridge <= 15.1.6, <= 16.0.5
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched