Executive brief
Adobe Bridge, a digital asset management application, is vulnerable to a security flaw that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized software execution, potentially compromising sensitive data or disrupting business operations.
Technical details
Adobe Bridge contains an Incorrect Authorization vulnerability (CWE-863) that can lead to arbitrary code execution. The flaw exists because the application fails to properly validate or authorize actions when processing specific file types. An attacker can exploit this by delivering a malicious file to a local user; once the user opens the file, the attacker's code executes with the privileges of the logged-in user. The vulnerability is characterized by a 'Changed' scope in the CVSS metric, indicating the impact extends beyond the Adobe Bridge application itself to the underlying operating system. Patches are available in versions 15.1.7 and 16.0.6.
Affected products
- Adobe Bridge <= 15.1.6, <= 16.0.5
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory