Junglewise Threat Intelligence

CVE-2026-48395: Adobe Bridge untrusted search path arbitrary code execution

CVE-2026-48395 · Severity: high · CVSS 8.6 · Published 2026-07-28

Technologies: Adobe Bridge. Vendors: Adobe.

Executive brief

Adobe Bridge, a professional asset management application, is affected by a security vulnerability that could allow an attacker to take control of a user's system. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could execute unauthorized commands or software with the same permissions as the logged-in user, potentially leading to data theft or full system compromise.

Technical details

Adobe Bridge is vulnerable to an Untrusted Search Path (CWE-426) flaw. The application incorrectly handles the search path when loading external resources or libraries, allowing an attacker to place a malicious file (such as a DLL) in a location that the application searches before legitimate system directories. The attack vector is local but requires user interaction (UI:R), where a victim must open a malicious file provided by the attacker. Successful exploitation results in arbitrary code execution with the privileges of the current user and carries a Changed Scope (S:C) impact. The vulnerability is addressed in versions 15.1.7 and 16.0.6.

Affected products

  • Adobe Bridge <= 15.1.6, <= 16.0.5

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory
  • 2026-07-28: patched

References

Related threats