Description
Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could have leveraged this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue did not require user interaction, but required the attacker to have access to the local environment the application is installed on.
Published: 2026-08-07
Score: 4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Incorrect Authorization flaw that allows a local attacker to bypass the Adobe Genuine Software Integrity Service's security checks, gaining unauthorized limited write access to protected files and components. The attacker does not need user interaction, but must have local access to the machine where the service runs.

Affected Systems

Adobe Genuine Software Integrity Service, distributed by Adobe, is affected. No specific version information is provided, so all installations of the service may be vulnerable.

Risk and Exploitability

The CVSS score of 4 indicates a low severity classification. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known public exploitation. Because the flaw requires local access, the attack vector involves a local attacker executing a crafted action that causes the service to write without proper authorization. No network exposure is required. Only an attacker who has local access to the machine where the service runs can exploit this vulnerability.

Generated by OpenCVE AI on August 7, 2026 at 21:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Genuine Software Integrity Service to the latest vendor release that includes the authorization fix.
  • Apply file system permissions so that only authorized privileged accounts can write to directories used by the service, ensuring no unrestricted write access.
  • Disable or uninstall the Adobe Genuine Software Integrity Service if it is not needed, to reduce the attack surface.
  • Enable audit logging for write operations performed by the service and review logs for anomalous activity on a regular basis.

Generated by OpenCVE AI on August 7, 2026 at 21:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could have leveraged this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue did not require user interaction, but required the attacker to have access to the local environment the application is installed on.
Title Adobe Genuine Software Integrity Service | CWE-863 Incorrect Authorization
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-07T21:01:43.262Z

Reserved: 2026-08-06T09:00:49.999Z

Link: CVE-2026-71381

cve-icon Vulnrichment

Updated: 2026-08-07T20:50:39.851Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T22:00:07Z

Weaknesses