Junglewise Threat Intelligence

CVE-2026-76196: Adobe Photoshop Mobile session fixation privilege escalation

CVE-2026-76196 · Severity: high · CVSS 7.4 · Published 2026-09-08

Executive brief

Photoshop Mobile, Adobe's mobile photo editing application, is vulnerable to session fixation attacks that could allow an attacker to escalate privileges and access sensitive user resources. An attacker would need to trick a user into visiting a malicious webpage to exploit this vulnerability, but successful exploitation could grant unauthorized access to user data and editing projects stored within the application.

Technical details

The vulnerability is a session fixation flaw in Photoshop Mobile that allows privilege escalation through scope change. Session fixation occurs when an attacker is able to set or predict a user's session identifier, then use that fixed session to impersonate the user with elevated privileges. The attack vector is network-based and requires user interaction—specifically, a victim must visit a malicious webpage crafted by the attacker. Exploitation depends on conditions beyond the attacker's control, suggesting additional prerequisites or user actions are necessary. Adobe has not publicly disclosed patch details in accessible sources at this time.

Affected products

  • Adobe Photoshop Mobile <UNKNOWN>

Timeline

  • 2026-09-08: disclosed: CVE-2026-76196 published

References

Related threats