CVE-2026-48349
published 2026-07-14CVE-2026-48349: Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit…
PriorityP345high8.1CVSS 3.1
AVLACHPRNUINSCCHIHAH
EPSS
0.19%
9.1th percentile
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_animate_2023 | <= 23.0.15 | — |
| adobe | adobe_animate_2024 | <= 24.0.13 | — |
| adobe | animate | >= 23.0.0 < 23.0.16 | 23.0.16 |
| adobe | animate | >= 24.0.0 < 24.0.14 | 24.0.14 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Animate 2023/2024 improper authorization
vuldb·2026-07-15·CVSS 8.1
CVE-2026-48349 [HIGH] Adobe Animate 2023/2024 improper authorization
A vulnerability labeled as problematic has been found in Adobe Animate 2023/2024. The impacted element is an unknown function. Executing a manipulation can lead to improper authorization.
The identification of this vulnerability is CVE-2026-48349. The attack can only be executed locally. There is no exploit available.
GHSA
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user.
ghsa_unreviewed·2026-07-14
CVE-2026-48349 [HIGH] CWE-863 Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user.
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-14
Published