Description
Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-28
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Bridge is vulnerable to an incorrect authorization flaw that can lead to privilege escalation. The flaw allows an attacker to gain unauthorized read and write access to files after the user opens a malicious file. This grants the attacker the ability to read or modify sensitive data within the application’s scope, thereby compromising confidentiality and integrity of resources. The weakness is classified as CWE‑863.

Affected Systems

Adversaries may target Adobe Bridge installations on any platform where the application is installed. Specific affected versions are not listed in the advisory, so assuming all current releases prior to the vendor’s patch are vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 8.2, indicating high severity, but its EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires the victim to open a malicious file, so user interaction is mandatory. Attackers must first craft or obtain a file that, when opened by Bridge, triggers the incorrect authorization and then perform unauthorized read or write operations within the application. Given the user interaction requirement and low exploit probability, the immediate risk is moderate, but the potential impact warrants timely remediation.

Generated by OpenCVE AI on August 3, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Bridge security update that addresses the incorrect authorization flaw.
  • Configure file scanning or sandboxing so that files are inspected before being opened by Bridge.
  • Limit user privileges so that Bridge runs with minimal access rights, reducing the damage from a successful privilege escalation.

Generated by OpenCVE AI on August 3, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Bridge | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Adobe Bridge Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-29T18:12:40.625Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48390

cve-icon Vulnrichment

Updated: 2026-07-29T18:12:36.383Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T19:17:35.123

Modified: 2026-08-03T13:36:49.923

Link: CVE-2026-48390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses