Description
Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-22
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Privilege escalation via server‑side request forgery leading to unauthorized write access
Action: Patch
AI Analysis

Impact

Premiere Pro is vulnerable to a server‑side request forgery that can allow an attacker to cause the application’s server to issue arbitrary HTTP requests. This flaw can be leveraged to perform privilege escalation and potentially write unauthorized data. Because the scope is changed, exploitation can affect system‑wide permissions beyond the original user privileges.

Affected Systems

Adobe Premiere is the impacted product. No specific affected version numbers are listed in the advisory, so all installed instances should be treated as vulnerable until a patch or update is applied.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high level of severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation does not require user interaction, implying that a remote attacker could exploit the flaw from their own network or via the service’s exposed interface. Attackers may construct crafted requests that the server forwards, potentially accessing internal resources or escalating privileges.

Generated by OpenCVE AI on September 22, 2026 at 20:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that addresses the SSRF flaw for Adobe Premiere Pro.
  • Restrict outbound network connections from the Premiere Pro application to prevent unintended server‑side requests.
  • If a patch cannot be applied immediately, block external request paths or disable features that allow the application to initiate outbound HTTP traffic.
  • Monitor logs for anomalous outgoing requests to detect potential exploitation attempts.

Generated by OpenCVE AI on September 22, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe premiere
Vendors & Products Adobe
Adobe premiere

Tue, 22 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Premiere Pro [NEEDS REVIEW: environment mismatch — product 'Premiere Pro' is only known to appear in the 'Bucket A' bucket but environment_type 'Desktop' is in the 'Bucket A' bucket. This changes the exploitation clause and/or ATO eligibility — verify before publishing.] is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Premiere Pro [NEEDS REVIEW: environment mismatch — product 'Premiere Pro' is only known to appear in the 'Bucket A' bucket but environment_type 'Desktop' is in the 'Bucket A' bucket. This changes the exploitation clause and/or ATO eligibility — verify before publishing.] is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
Title Premiere Pro | Server-Side Request Forgery (SSRF) (CWE-918)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-23T03:56:02.089Z

Reserved: 2026-09-01T16:49:48.598Z

Link: CVE-2026-84395

cve-icon Vulnrichment

Updated: 2026-09-22T19:15:33.869Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:54.260

Modified: 2026-09-23T04:17:56.257

Link: CVE-2026-84395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T21:45:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)