Impact
An uncontrolled search path element flaw allows an attacker to supply a malicious executable in a directory that Photoshop scans before the standard system directories. When a user opens a crafted file, Photoshop resolves the path to the attacker‑supplied binary and runs it with the current user's privileges, enabling arbitrary code execution. The flaw has the scope changed, meaning it can also affect system files if the attacker escalates privileges.
Affected Systems
Adobe Photoshop 2025 and Adobe Photoshop 2026 for desktop systems are affected. No more granular version information is available, so all releases within the 2025/2026 series should be considered vulnerable until an official patch is confirmed.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. Exploitation requires user interaction—specifically the victim opening a malicious file. The EPSS score is not available, so public exploit data is currently lacking, and the vulnerability is not listed in the CISA KEV catalog. However, the local attack vector combined with scope change means the risk remains significant, especially for environments that permit users to open untrusted Photoshop files.
OpenCVE Enrichment