Description
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-28
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Bridge has an Untrusted Search Path flaw that allows an attacker to run arbitrary code in the context of the current user. By supplying a specially crafted file, a low‑privileged user who opens that file can cause Bridge to load a malicious executable from an untrusted directory. The vulnerability can trigger local code execution and, because scope is changed, may lead to elevation of privileges within the user’s session.

Affected Systems

Adobe Bridge from Adobe Inc. The advisory did not list specific version numbers; any installation of Bridge is potentially affected.

Risk and Exploitability

The flaw carries a CVSS score of 8.2, reflecting a high severity attack with full user‑level privilege. Its EPSS score is below 1 percent, meaning real‑world exploitation is currently unlikely but cannot be dismissed. The vulnerability is not found in the CISA KEV list. It requires that a victim open a malicious file, so the vector is user‑interaction, or “click‑through.” If an attacker can co‑ordinate this action, the code will execute with the victim’s rights, potentially leading to data theft or further lateral movement.

Generated by OpenCVE AI on August 3, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Adobe Bridge security update released in APSB26-89 to eliminate the untrusted search path flaw.
  • Remove or relocate any directories that are included in Bridge’s search path to trusted locations and avoid placing unknown executables in those directories.
  • Restrict user accounts from writing to or executing from the directories that Bridge scans, and consider using application whitelisting to prevent execution of untrusted code.

Generated by OpenCVE AI on August 3, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Bridge | Untrusted Search Path (CWE-426)
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-29T03:56:02.075Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48391

cve-icon Vulnrichment

Updated: 2026-07-28T18:31:04.044Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T19:17:35.243

Modified: 2026-08-03T13:36:58.373

Link: CVE-2026-48391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses