Description
Bridge is affected by an Uncontrolled Recursion vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an uncontrolled recursion that can cause a stack overflow and, if triggered, allows an attacker to execute arbitrary code in the context of the current user. As a result, confidentiality, integrity, and availability of the affected system can be compromised. The weakness is classified as CWE‑674.

Affected Systems

Adobe Bridge applications of all released versions are potentially affected; specific version information is not specified in the advisory. The flaw applies to all platforms supported by Adobe Bridge, including Windows and macOS.

Risk and Exploitability

The CVSS score is 7.8, indicating high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires the victim to open a maliciously crafted file, so a social engineering or phishing scenario is the likely attack vector.

Generated by OpenCVE AI on September 22, 2026 at 20:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Adobe Bridge update released in Adobe's 2026‑06 security bulletin APSB26‑148 that resolves the recursion issue.
  • If an update cannot be applied immediately, disable Adobe Bridge or restrict its use to accounts that only handle trusted files, preventing the execution of unknown files until the patch is available.
  • Employ a sandbox or file‑scanning solution to verify files before opening them in Adobe Bridge, reducing the risk that a malicious file will be executed.

Generated by OpenCVE AI on September 22, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Bridge
Vendors & Products Adobe
Adobe adobe Bridge

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Bridge is affected by an Uncontrolled Recursion vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Bridge | Uncontrolled Recursion (CWE-674)
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Bridge
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-23T03:56:13.304Z

Reserved: 2026-08-18T01:29:54.615Z

Link: CVE-2026-75655

cve-icon Vulnrichment

Updated: 2026-09-22T19:26:20.755Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:45.383

Modified: 2026-09-23T04:17:44.613

Link: CVE-2026-75655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:00:08Z

Weaknesses