Impact
Adobe Illustrator Desktop is vulnerable to an improper input validation flaw that can lead to arbitrary code execution when the user opens a crafted file. The flaw allows an attacker to inject malicious code into the application’s processing path, enabling execution within the context of the current user. Successful exploitation can compromise user data and facilitate further attacks, and the vulnerability’s scope is changed.
Affected Systems
Both Adobe Illustrator Desktop 2025 and 2026 contain the input validation bug that can be triggered by malicious files. No other Illustrator releases are listed as affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the flaw requires the victim to open a malicious file, which lowers the probability of successful attack attempts. The EPSS score is currently unavailable and the vulnerability is not in the CISA KEV catalog, indicating that large‑scale exploitation has not been observed yet. Nevertheless, the change in scope and ability to run code arbitrarily mean the vulnerability poses a serious risk to systems that use Illustrator when exposed to untrusted documents.
OpenCVE Enrichment