Impact
Adobe Bridge is affected by a path traversal flaw that allows a malicious file to reference directories outside the intended sandbox. When a victim opens a crafted file, the application can resolve a pathname to any location on the file system and read its contents. This results in a confidentiality breach where sensitive data or configuration files may be exfiltrated.
Affected Systems
All installations of Adobe Bridge are impacted, regardless of the operating system or build. The advisory does not list specific versions, so any currently deployed release should be considered vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating high severity, and an EPSS value of less than 1 %, suggesting exploitation likelihood remains low at present. It is not present in CISA’s KEV catalog. Exploit requires user interaction—as the victim must open a malicious file—so the attack vector is primarily social engineering or drive‑by collection of suspicious files. Given the potential for sensitive data disclosure and the lack of widespread exploitation evidence, organizations should treat this as a high‑risk flaw and remediate promptly.
OpenCVE Enrichment