Description
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-28
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Bridge suffers an out-of-bounds write that allows an attacker to write data beyond the bounds of a memory buffer, enabling the execution of arbitrary code in the context of the current user. The impact is the loss of confidentiality, integrity, and availability for the user session, as the attacker could run any code the user is authorized to execute. This weakness corresponds to CWE‑787, which covers out‑of‑bounds writes.

Affected Systems

The vulnerability affects Adobe Bridge products released by Adobe Inc. The specific affected versions are not listed in the advisory, so all current releases prior to the published patch should be treated as vulnerable until verified otherwise.

Risk and Exploitability

The CVSS score of 7.8 categorizes the flaw as high severity. The EPSS score is less than 1 %, indicating a very low probability of exploitation in the wild, though the failure requires user interaction to open a malicious file. The typical attack vector involves tricking a user into opening a maliciously crafted file with Adobe Bridge, which triggers the out-of-bounds write and leads to arbitrary code execution. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation. Nonetheless, the potential to run arbitrary code remains significant, so organizations should treat it as a high‑risk issue pending a vendor fix.

Generated by OpenCVE AI on August 3, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Adobe Bridge update or security patch from Adobe’s official security portal, as detailed in the Adobe Bridge security advisory.
  • Avoid opening or executing files from untrusted or unknown sources; treat all files as potentially malicious until verified.
  • Configure system or application settings to disable or restrict script execution within Adobe Bridge, or enforce application whitelisting to prevent the load of unauthorized code.

Generated by OpenCVE AI on August 3, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Bridge | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-29T03:56:04.059Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48392

cve-icon Vulnrichment

Updated: 2026-07-28T18:45:48.787Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T19:17:35.377

Modified: 2026-08-03T13:36:54.583

Link: CVE-2026-48392

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses