Description
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Animate suffers from a weakness in its authorization logic that allows an attacker to run arbitrary code under the current user’s permission level. A malicious file crafted by the attacker, when opened in Animate, triggers the exploit and bypasses intended access controls, enabling code execution as the victim. This is a classic CWE‑863 flaw where insufficient checks against user privileges are performed, undermining the application’s security guarantees.

Affected Systems

The flaw impacts Adobe Animate versions 2023 and 2024 released by Adobe Systems. Any installation of those major releases is potentially affected; no specific sub‑version details are provided, so a broad range of installations could be vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.7, indicating high severity, but its EPSS score is below 1%, suggesting a low probability of exploitation in the wild. It is not currently listed in the CISA KEV catalog, and exploitation requires user interaction—specifically, a victim must open a malicious file. Once the file is opened, the scope changes, giving the attacker the ability to execute code with the victim’s rights, which can compromise system integrity and confidentiality.

Generated by OpenCVE AI on July 31, 2026 at 05:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe security patch released in APSB26‑83 that addresses the incorrect authorization flaw in Animate 2023 and 2024.
  • Configure Adobe Animate to require file signatures or explicit user authentication before opening files from external sources.
  • Limit user rights in the system so that only authorized personnel can open or execute custom animate files; consider running Animate in a sandboxed or restricted profile until the patch is applied.

Generated by OpenCVE AI on July 31, 2026 at 05:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Animate 2023
Adobe adobe Animate 2024
Vendors & Products Adobe
Adobe adobe Animate 2023
Adobe adobe Animate 2024

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Animate | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Animate 2023 Adobe Animate 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:38:32.924Z

Reserved: 2026-05-21T15:28:38.140Z

Link: CVE-2026-48348

cve-icon Vulnrichment

Updated: 2026-07-15T10:38:27.806Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses