Description
Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-07-28
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Bridge suffers from an Incorrect Authorization flaw that can be triggered when a user opens a specially crafted file. The vulnerability allows a malicious file to bypass the expected access controls and execute arbitrary code with the privileges of the current user, and the scope of the vulnerability is changed.

Affected Systems

The affected product is Adobe Bridge. No specific version information was provided by the vendor, so any installation of Adobe Bridge that has not yet received the vendor’s security update can be assumed vulnerable.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attacking this flaw requires user interaction—namely, the victim must open a malicious file—so the risk also depends on user caution. Once executed, the attacker runs code in the user’s context, providing the potential for system‑wide compromise if the user has elevated privileges.

Generated by OpenCVE AI on August 3, 2026 at 14:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Adobe Bridge security update that addresses the incorrect authorization flaw.
  • Configure the operating system or file‑type policies to reject or quarantine unsigned or unknown files before they are opened by Adobe Bridge.
  • Apply least‑privilege principles or sandbox the Adobe Bridge process so that any code it runs cannot affect critical system components.

Generated by OpenCVE AI on August 3, 2026 at 14:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Bridge | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-29T03:56:07.353Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48396

cve-icon Vulnrichment

Updated: 2026-07-28T18:34:33.183Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T19:17:35.870

Modified: 2026-08-03T13:37:05.503

Link: CVE-2026-48396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T14:45:04Z

Weaknesses