Description
Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Creative Cloud Desktop contains an uncontrolled search‑path element that allows an attacker to manipulate the directories searched for executables. The flaw can lead to arbitrary code execution in the context of the logged‑in user. The CVE description indicates that exploitation does not require user interaction but depends on conditions beyond the attacker’s control, and the scope is changed.

Affected Systems

Adobe Creative Cloud Desktop is the affected product. No specific version numbers are provided, so all installations of Creative Cloud Desktop are considered vulnerable until Adobe releases a patch.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score being less than 1 % suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is local or requires the attacker to initially influence the environment of the user’s workstation. The change in scope increases the potential breadth of compromise if the external conditions that enable exploitation are satisfied.

Generated by OpenCVE AI on July 31, 2026 at 04:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Creative Cloud Desktop to the latest version that includes the fix.
  • Restrict the system’s environment variables or the application’s search path so that only trusted directories are used during executable resolution.
  • Review and tighten permissions on the application’s installation directory to prevent unauthorized placement and execution of files.

Generated by OpenCVE AI on July 31, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe creative Cloud
Vendors & Products Adobe
Adobe creative Cloud

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Title Creative Cloud Desktop | Uncontrolled Search Path Element (CWE-427)
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Creative Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:35:08.685Z

Reserved: 2026-05-21T15:28:38.132Z

Link: CVE-2026-48272

cve-icon Vulnrichment

Updated: 2026-07-15T10:35:03.616Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:03Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element