Description
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The identified special elements used in an OS command, classified as CWE-78, allow an attacker to inject arbitrary operating system commands through a malicious file processed by Adobe Animate. If a user opens such a file, the application may execute the injected commands with the privileges of the current user, potentially enabling full system compromise.

Affected Systems

The vulnerability targets Adobe Animate 2023 and 2024 releases. Systems running these versions, irrespective of platform, are susceptible. No further product details are presently disclosed.

Risk and Exploitability

With a CVSS score of 7.7, the vulnerability poses a high risk for users who interact with malicious files. Its EPSS score is below 1% and it is not listed in the CISA KEV catalog, indicating limited observed exploitation. The change in scope allows execution in the context of the current user, so based on the description, it is inferred that a targeted social engineering or phishing campaign that convinces a user to open a crafted file could lead to remote code execution. The CVE description does not specify supported operating systems; however, any platform where Adobe Animate executes OS commands could be impacted.

Generated by OpenCVE AI on July 31, 2026 at 05:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update released by Adobe for Animate 2023 and 2024 to eliminate the command injection flaw.
  • Avoid opening or executing untrusted .aep files while using Adobe Animate, especially from unknown or unverified sources.
  • Maintain up-to-date endpoint protection and conduct regular file integrity monitoring scripts.

Generated by OpenCVE AI on July 31, 2026 at 05:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Animate 2023
Adobe adobe Animate 2024
Vendors & Products Adobe
Adobe adobe Animate 2023
Adobe adobe Animate 2024

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Animate 2023 Adobe Animate 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:38:59.616Z

Reserved: 2026-05-21T15:28:38.140Z

Link: CVE-2026-48347

cve-icon Vulnrichment

Updated: 2026-07-15T10:38:54.560Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')