Description
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.
Published: 2026-04-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Photoshop Installer was impacted by an uncontrolled search path element flaw that could allow arbitrary code execution by the current user. During the installation process, the installer searches for required components and may load a malicious library that an attacker places in a directory prioritized in the search path. This vulnerability, identified as CWE‑427, requires the victim to run the installer, meaning user interaction is necessary, and its scope is changed.

Affected Systems

Systems impacted are those running Adobe Photoshop Installer from Adobe. No specific version information is supplied; users who routinely download and run the installer are potentially exposed.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. Exploitation requires user interaction; the attacker must persuade a user to execute the installer on the target machine. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, but the high severity score suggests that the vulnerability can be leveraged for significant damage.

Generated by OpenCVE AI on July 31, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Adobe Photoshop Installer from Adobe’s official website.
  • Configure application whitelisting (e.g., AppLocker or Software Restriction Policies) so that only signed Adobe installers are allowed to run.
  • Restrict the PATH environment variable to trusted directories and prevent modification by installers.
  • Verify that non‑Adobe installers are blocked and that system updates are applied regularly.

Generated by OpenCVE AI on July 31, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. A low-privileged local attacker could have exploited this vulnerability by manipulating the search path used by the application to locate critical resources, potentially causing unauthorized code execution. Exploitation of this issue required user interaction in that a user had to be running the installer. Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 22 Apr 2026 17:30:00 +0000


Thu, 16 Apr 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Photoshop Installer
Vendors & Products Adobe
Adobe adobe Photoshop Installer

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
Description Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. A low-privileged local attacker could have exploited this vulnerability by manipulating the search path used by the application to locate critical resources, potentially causing unauthorized code execution. Exploitation of this issue required user interaction in that a user had to be running the installer.
Title Photoshop Installer | CWE-427: Uncontrolled Search Path Element
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Photoshop Installer
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-20T18:03:06.223Z

Reserved: 2026-03-30T17:30:36.491Z

Link: CVE-2026-34632

cve-icon Vulnrichment

Updated: 2026-04-22T16:23:58.307Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-15T19:16:36.223

Modified: 2026-06-17T10:39:21.260

Link: CVE-2026-34632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T18:00:08Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element