Description
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-14
Score: 7.9 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Animate is affected by an untrusted search path vulnerability that allows an attacker to execute arbitrary code in the context of the current user. The flaw occurs when the application searches for executable files in a non‑secured directory, enabling a malicious file to be invoked during normal operation. Because the vulnerability changes scope, the attacker could also gain elevated privileges on the system.

Affected Systems

Adobe Animate 2023 and Adobe Animate 2024 are impacted. No specific sub‑versions are listed beyond these product releases.

Risk and Exploitability

With a CVSS score of 7.9, the vulnerability presents high severity, but its EPSS score of less than 1% indicates that it is currently unlikely to be widely exploited, and it is not listed in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious file. Once executed, code runs under the user's privileges and may elevate privileges due to the scope change. The attack path relies on untrusted directories in the execution search path, making exploitation possible if such directories are writable or accessible.

Generated by OpenCVE AI on July 31, 2026 at 05:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe security update for Animate 2023 or 2024 as published by Adobe.
  • Instruct users to avoid opening unknown Animate files and only open files from trusted sources.
  • Remove or correct any writable directories from Adobe Animate’s search path and ensure that directories used for executable lookup have appropriate permissions to prevent unintended execution.

Generated by OpenCVE AI on July 31, 2026 at 05:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Animate 2023
Adobe adobe Animate 2024
Vendors & Products Adobe
Adobe adobe Animate 2023
Adobe adobe Animate 2024

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Animate | Untrusted Search Path (CWE-426)
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Adobe Animate 2023 Adobe Animate 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:39:13.282Z

Reserved: 2026-05-21T15:28:38.140Z

Link: CVE-2026-48346

cve-icon Vulnrichment

Updated: 2026-07-15T10:39:08.117Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses