Description
Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-09-08
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Apply Patch
AI Analysis

Impact

An uncontrolled search path element flaw allows an attacker to supply a malicious executable in a directory that Photoshop scans before the standard system directories. When a user opens a crafted file, Photoshop resolves the path to the attacker‑supplied binary and runs it with the current user's privileges, enabling arbitrary code execution. The flaw has the scope changed, meaning it can also affect system files if the attacker escalates privileges.

Affected Systems

Adobe Photoshop 2025 and Adobe Photoshop 2026 for desktop systems are affected. No more granular version information is available, so all releases within the 2025/2026 series should be considered vulnerable until an official patch is confirmed.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. Exploitation requires user interaction—specifically the victim opening a malicious file. The EPSS score is not available, so public exploit data is currently lacking, and the vulnerability is not listed in the CISA KEV catalog. However, the local attack vector combined with scope change means the risk remains significant, especially for environments that permit users to open untrusted Photoshop files.

Generated by OpenCVE AI on September 9, 2026 at 13:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Adobe Photoshop update that addresses the uncontrolled search path issue.
  • Configure Photoshop’s search path to include only trusted directories and remove any entries that can be controlled by an attacker.
  • Educate users about the dangers of opening unknown Photoshop files and enforce policies that block such files from untrusted locations.

Generated by OpenCVE AI on September 9, 2026 at 13:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe photoshop 2025
Adobe photoshop 2026
Vendors & Products Adobe photoshop 2025
Adobe photoshop 2026

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe photoshop
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Photoshop Desktop | Uncontrolled Search Path Element (CWE-427)
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Photoshop Photoshop 2025 Photoshop 2026
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-09T09:54:43.305Z

Reserved: 2026-08-19T11:09:31.826Z

Link: CVE-2026-76199

cve-icon Vulnrichment

Updated: 2026-09-09T09:51:43.977Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T20:18:24.280

Modified: 2026-09-11T18:32:35.897

Link: CVE-2026-76199

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:07:29Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element