Description
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.
Published: 2026-07-28
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Photoshop Installer contains an uncontrolled search path element flaw that allows an attacker to place a malicious library in a directory searched by the installer. If the installer loads that library, the code inside runs with the privileges of the user executing the installer, potentially compromising the entire system. The vulnerability is classified as CWE‑427 and carries a CVSS score of 8.6, indicating a high‑severity flaw. Because the installer must be run by a user and the flaw changes the permission scope, the impact reaches system resources.

Affected Systems

The affected product is the Adobe Photoshop Installer. All versions that have not yet received a patch for this uncontrolled search path element are vulnerable. Users who download or run the installer are at risk. No specific version numbers are listed in the vendor’s disclosure.

Risk and Exploitability

The flaw requires user interaction and is therefore of the local attack vector type. Once the attacker places a malicious library in a location the installer searches, the installer will load it, executing arbitrary code under the current user’s context. The CVSS score of 8.6 signals high severity, but the EPSS score of less than 1% shows that known exploitation attempts are very rare. The vulnerability is not yet listed in CISA’s KEV catalog, meaning it has not been confirmed as actively exploited in the wild.

Generated by OpenCVE AI on August 3, 2026 at 14:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest Adobe Photoshop installer that includes the fix for the uncontrolled search path element flaw.
  • Restrict the directories searched by the installer by ensuring no writable or untrusted folders are present in the system path before execution; remove such directories from the search path.
  • Implement application whitelisting or control software restriction policies to limit the ability of the installer to load libraries from unauthorized locations.

Generated by OpenCVE AI on August 3, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Photoshop Installer
Vendors & Products Adobe
Adobe adobe Photoshop Installer

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.
Title Photoshop Installer | CWE-427: Uncontrolled Search Path Element
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Photoshop Installer Photoshop Installer
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-28T19:35:18.940Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48388

cve-icon Vulnrichment

Updated: 2026-07-28T19:35:12.238Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T18:17:20.887

Modified: 2026-08-05T19:12:27.330

Link: CVE-2026-48388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element