Description
Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Bridge contains an untrusted pointer dereference flaw that can lead to arbitrary code execution in the user’s context. The vulnerability is caused by the application dereferencing a pointer derived from untrusted input when processing a file, allowing an attacker to craft a malicious file that triggers the unsafe operation. Successful exploitation would provide the attacker with the privileges of the user who opens the file.

Affected Systems

Adobe Bridge is affected. The advisory lists Adobe Bridge as the impacted product, but no specific version numbers are provided; therefore all versions of Adobe Bridge that fall under the scope of the Adobe security advisory are potentially at risk until a vendor patch is released.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests that known exploitation is very unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to open a specially crafted file, so the attack vector involves user interaction, typically through social engineering or accidental file download. The overall risk is moderate, with high impact if the flaw is exploited, but limited by the need for the user to intentionally launch the malicious file.

Generated by OpenCVE AI on July 31, 2026 at 04:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Bridge to the latest patched version as detailed in the Adobe security advisory.
  • Configure Adobe Bridge to prompt before opening files or disable automatic opening of unknown documents, if available in the application’s settings.
  • Avoid opening any files from untrusted or unknown sources, and consider restricting the use of Adobe Bridge to only vetted content.

Generated by OpenCVE AI on July 31, 2026 at 04:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Bridge | Untrusted Pointer Dereference (CWE-822)
Weaknesses CWE-822
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:31:53.182Z

Reserved: 2026-05-21T15:28:38.139Z

Link: CVE-2026-48340

cve-icon Vulnrichment

Updated: 2026-07-15T10:31:47.522Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:51Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference