CVE-2026-48348
published 2026-07-14CVE-2026-48348: Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit…
PriorityP342high7.7CVSS 3.1
AVLACHPRNUIRSCCHIHAH
EPSS
0.17%
6.2th percentile
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_animate_2023 | <= 23.0.15 | — |
| adobe | adobe_animate_2024 | <= 24.0.13 | — |
| adobe | animate | >= 23.0.0 < 23.0.16 | 23.0.16 |
| adobe | animate | >= 24.0.0 < 24.0.14 | 24.0.14 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Animate 2023/2024 File improper authorization
vuldb·2026-07-15·CVSS 7.7
CVE-2026-48348 [HIGH] Adobe Animate 2023/2024 File improper authorization
A vulnerability identified as problematic has been detected in Adobe Animate 2023/2024. The affected element is an unknown function of the component File Handler. Performing a manipulation results in improper authorization.
This vulnerability was named CVE-2026-48348. The attack needs to be approached locally. There is no available exploit.
GHSA
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user.
ghsa_unreviewed·2026-07-14
CVE-2026-48348 [HIGH] CWE-863 Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user.
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-14
Published