CVE-2026-48390
published 2026-07-28CVE-2026-48390: Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain…
PriorityP343high8.2CVSS 3.1
AVLACLPRNUIRSCCHIHAN
EPSS
0.19%
8.9th percentile
Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_bridge | <= 16.0.5 | — |
| adobe | bridge | < 15.1.7 | 15.1.7 |
| adobe | bridge | >= 16.0 < 16.0.6 | 16.0.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.
ghsa_unreviewed·2026-07-28
CVE-2026-48390 [HIGH] CWE-863 Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation.
Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
VulDB
Adobe Bridge improper authorization
vuldb·2026-07-28·CVSS 8.2
CVE-2026-48390 [HIGH] Adobe Bridge improper authorization
A vulnerability was found in Adobe Bridge. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper authorization.
This vulnerability is known as CVE-2026-48390. Attacking locally is a requirement. No exploit is available.
No detection rules found.
No public exploits indexed.
2026-07-28
Published