Description
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.
Published: 2026-09-08
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a session fixation flaw that enables an attacker to hijack a legitimate user’s session by forcing the use of a chosen session identifier. By obtaining a valid session, the attacker can access sensitive resources as if they were the authenticated user, thereby elevating privileges. The flaw is classified as CWE-384 and can grant unauthorized data access or further compromise of the device.

Affected Systems

Adobe Photoshop Mobile for Android. All installations are considered vulnerable because no specific version range is supplied.

Risk and Exploitability

The CVSS score of 7.4 indicates a substantial impact when conditions are met. Exploitation requires the victim to interact with a malicious webpage, meaning the attacker cannot trigger the flaw remotely alone. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet, but the requirement for user interaction still presents a significant risk.

Generated by OpenCVE AI on September 9, 2026 at 02:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Photoshop Mobile to the latest version that includes the session fixation fix.
  • If an update is not immediately possible, clear the application’s cache and data to invalidate any active sessions and force creation of a new session.
  • Avoid loading untrusted or suspicious webpages within the app, and keep the device’s web browser and operating system up to date to reduce the risk of malicious content triggering the flaw.

Generated by OpenCVE AI on September 9, 2026 at 02:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe photoshop Mobile
CPEs cpe:2.3:a:adobe:photoshop_mobile:*:*:*:*:*:android:*:*
Vendors & Products Adobe
Adobe photoshop Mobile

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.
Title Photoshop Mobile | Session Fixation (CWE-384)
Weaknesses CWE-384
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Photoshop Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:45.080Z

Reserved: 2026-08-19T11:08:31.955Z

Link: CVE-2026-76196

cve-icon Vulnrichment

Updated: 2026-09-09T09:52:08.892Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:33.380

Modified: 2026-09-09T13:56:50.440

Link: CVE-2026-76196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses