Description
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Bridge is vulnerable to an out‑of‑bounds write that could result in arbitrary code execution in the context of the current user. The flaw originates from insufficient bounds checking when parsing certain input data from a file, and successful exploitation would allow an attacker to gain full control of affected systems, compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability applies to Adobe Bridge for all supported operating systems. The affected product is Adobe Bridge; specific affected versions are not listed in the public data and should be cross‑checked against Adobe’s advisory for the latest fix.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score is below 1 %, suggesting that, at present, the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Because an attacker must trick a user into opening a crafted file, the attack vector is user‑interaction‑dependent; however, once executed, the code runs with the user’s rights.

Generated by OpenCVE AI on July 31, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Adobe Bridge update that fixes CVE‑2026 described in the Adobe advisory.
  • Configure user awareness training to avoid opening unknown or unsigned Bridge files.
  • Configure application whitelisting or file‑type restrictions to block execution of untrusted files by Adobe Bridge where possible.

Generated by OpenCVE AI on July 31, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Bridge | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:32:49.236Z

Reserved: 2026-05-21T15:28:38.136Z

Link: CVE-2026-48311

cve-icon Vulnrichment

Updated: 2026-07-15T10:32:43.607Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:56Z

Weaknesses