Description
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-14
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Illustrator’s vulnerability arises from improper validation of file input. An attacker can craft a malicious file that, when a user opens it, causes arbitrary code execution in the user’s context, potentially granting the attacker elevated privileges or full control over the victim’s account or session. This weakness, identified as CWE‑20, alters the scope of the affected system when exploited.

Affected Systems

The flaw affects Adobe Illustrator Desktop versions 2025 and 2026. No specific patch version numbers are listed in the advisory, but the issue applies to all installations of these releases that have not been updated with the later security release.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. The EPSS score of less than 1 % indicates a low likelihood of exploitation. The vulnerability has not yet been listed in the CISA KEV catalog. Exploitation requires user interaction – the victim must open the malicious file. Once the file is opened, the attacker can run arbitrary code in the context of the current user, potentially gaining elevated access or control over the victim’s account or session. The change in scope highlights the importance of applying the update as soon as it is available.

Generated by OpenCVE AI on August 4, 2026 at 07:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Adobe Illustrator security update as published in the official Adobe advisory—this contains the required fix for the improper input validation flaw.
  • Disable or carefully control file‑type auto‑open features for Illustrator, and educate users to avoid opening unknown or suspicious files.
  • Employ endpoint protection that can detect and block the malicious file signature if the update cannot be applied immediately.

Generated by OpenCVE AI on August 4, 2026 at 07:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026
Vendors & Products Adobe
Adobe illustrator Desktop 2025
Adobe illustrator Desktop 2026

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Illustrator | Improper Input Validation (CWE-20)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Illustrator Desktop 2025 Illustrator Desktop 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-21T21:35:12.679Z

Reserved: 2026-05-21T15:28:38.139Z

Link: CVE-2026-48334

cve-icon Vulnrichment

Updated: 2026-07-15T10:41:40.347Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T07:15:03Z

Weaknesses
  • CWE-20

    Improper Input Validation