Description
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-28
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Bridge contains an Untrusted Search Path flaw that can allow an attacker to execute arbitrary code with the privileges of the user who opens a malicious file. The weakness is a classic untrusted search path error classified as CWE‑426, and because the exploitation can result in system‑wide code execution, it escalates the security scope.

Affected Systems

The vulnerability affects Adobe Bridge installations. No specific version range is listed in the advisory data; users should consult the Adobe security bulletin for detailed version information and ensure the latest released version is installed.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests a low, but non‑zero, probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to open a crafted file; the likely attack vector is user‑directed rather than network‑based, which is inferred from the need for user interaction. If executed, the flaw permits arbitrary code execution in the context of the current user, potentially compromising the entire system.

Generated by OpenCVE AI on August 3, 2026 at 14:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe’s security update for Bridge as soon as it is available
  • Upgrade to the latest released version of Adobe Bridge if a patch has been issued
  • Avoid opening Bridge files from untrusted or unknown sources

Generated by OpenCVE AI on August 3, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Bridge | Untrusted Search Path (CWE-426)
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-29T18:12:28.635Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48395

cve-icon Vulnrichment

Updated: 2026-07-29T18:12:25.494Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T19:17:35.753

Modified: 2026-08-03T13:36:47.150

Link: CVE-2026-48395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses