Description
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Illustrator is vulnerable to an untrusted search path flaw (CWE-426) that allows a crafted file to execute arbitrary code in the context of the user who opens it. The flaw changes scope, giving the attacker the same privileges as the target user and enabling full control over the system. If exploited, malicious code could run with the victim’s user rights, potentially leading to data theft, system compromise, or further lateral movement.

Affected Systems

Adobe Illustrator Desktop 2025 and Adobe Illustrator Desktop 2026 are affected. No information is provided regarding the availability of patches or updates in this data set.

Risk and Exploitability

With a CVSS score of 8.6 the vulnerability is considered high severity. The EPSS score of < 1% indicates a low probability of exploitation at this time, and the issue is not currently listed in CISA’s KEV catalog. The likely attack vector requires the victim to open a malicious Illustrator file, so user interaction is a prerequisite. Because the effect is code execution under the current user’s privileges, the impact is serious if a user does fall for the lure.

Generated by OpenCVE AI on July 31, 2026 at 04:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Illustrator to the latest version that includes the security fix.
  • Restrict Illustrator’s search paths or employ application whitelisting to prevent execution of untrusted binaries.
  • Train users to avoid opening unknown or suspicious Illustrator files and enforce file‑level scanning on endpoints.

Generated by OpenCVE AI on July 31, 2026 at 04:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026
Vendors & Products Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Illustrator | Untrusted Search Path (CWE-426)
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Illustrator Desktop 2025 Illustrator Desktop 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:41:31.837Z

Reserved: 2026-05-21T15:28:38.133Z

Link: CVE-2026-48275

cve-icon Vulnrichment

Updated: 2026-07-15T10:41:27.268Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T04:45:17Z

Weaknesses