Description
Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require user interaction, but requires the attacker to access the target desktop system locally (e.g., keyboard, console), or remotely (e.g., SMB).
Published: 2026-08-07
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Incorrect Authorization flaw in the Adobe Genuine Software Integrity Service that allows an attacker to bypass security checks and gain unauthorized limited write access. This security feature bypass can be achieved without user interaction, but the attacker must have local or remote SMB access to the target desktop system. If exploited, the attacker could write to protected files or components controlled by the service, thereby compromising the integrity of the system.

Affected Systems

Adobe Genuine Software Integrity Service, distributed by Adobe, is affected. No specific version information is provided, so all installations of the service may be vulnerable.

Risk and Exploitability

The CVSS score of 4 indicates a low severity classification. The EPSS score is less than 1%, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known public exploitation. Because the flaw requires local or SMB-access, the attack vector involves a local or remote attacker executing a crafted action that causes the service to write without proper authorization. No network exposure is required beyond SMB. Only an attacker who has local or remote SMB access to the machine where the service runs can exploit this vulnerability.

Generated by OpenCVE AI on August 17, 2026 at 20:45 UTC.

Remediation

Vendor Solution

No action is required of Adobe app users to received the fixed version of AGS; it receives automatic updates.


OpenCVE Recommended Actions

  • No action required; the Adobe Genuine Software Integrity Service automatically downloads and installs the patched version through its update mechanism.
  • Confirm that the service remains enabled and not disabled, allowing automatic updates to be applied.
  • If desired, restrict write permissions on directories used by the service to further limit potential impact, although this does not address the underlying authorization flaw.

Generated by OpenCVE AI on August 17, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
References

Mon, 17 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could have leveraged this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue did not require user interaction, but required the attacker to have access to the local environment the application is installed on. Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require user interaction, but requires the attacker to access the target desktop system locally (e.g., keyboard, console), or remotely (e.g., SMB).
References

Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe genuine Integrity Service
Vendors & Products Adobe
Adobe genuine Integrity Service

Fri, 07 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could have leveraged this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue did not require user interaction, but required the attacker to have access to the local environment the application is installed on.
Title Adobe Genuine Software Integrity Service | CWE-863 Incorrect Authorization
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Adobe Genuine Integrity Service
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-17T15:02:03.308Z

Reserved: 2026-08-06T09:00:49.999Z

Link: CVE-2026-71381

cve-icon Vulnrichment

Updated: 2026-08-07T20:50:39.851Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-07T21:17:30.147

Modified: 2026-08-17T15:16:57.490

Link: CVE-2026-71381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T20:45:17Z

Weaknesses