Description
Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Animate contains a path‑traversal flaw (CWE‑22) that allows a crafted animation file to reference directories outside the intended sandbox. When the victim opens the malicious file, the software can read sensitive files or execute code with the privileges of the current user. Because the vulnerability is a scope‑changing flaw, it may elevate privileges beyond the current user, but the advisory does not specify the exact level of privilege escalation, leaving uncertainty.

Affected Systems

Adobe Animate desktop versions 2023 and 2024 are affected. All builds released during those years are considered vulnerable unless a later update explicitly removes the flaw.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is scope‑changing, an attacker might be able to achieve privilege escalation beyond the current user; however, the extent of this elevation is not detailed in the advisory. Effective exploitation still requires a user to open a malicious animation file, after which the software could traverse directories or execute code as that user.

Generated by OpenCVE AI on July 31, 2026 at 05:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe Animate update that addresses CVE‑2026‑48350 as published in the Adobe security advisory.
  • If a patch is unavailable, run Adobe Animate in a sandboxed environment or restrict its access to a safe directory to contain any path traversal attempts.
  • Instruct users to verify the source of animation files, avoid opening files from untrusted parties, and ensure antivirus or security software scans files before they are opened.

Generated by OpenCVE AI on July 31, 2026 at 05:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Animate 2023
Adobe adobe Animate 2024
Vendors & Products Adobe
Adobe adobe Animate 2023
Adobe adobe Animate 2024

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Animate 2023 Adobe Animate 2024
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:40:10.147Z

Reserved: 2026-05-21T15:28:38.140Z

Link: CVE-2026-48350

cve-icon Vulnrichment

Updated: 2026-07-15T10:40:03.415Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:15:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')