CVE-2026-48391
published 2026-07-28CVE-2026-48391: Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged…
PriorityP340high8.2CVSS 3.1
AVLACLPRLUIRSCCHIHAH
EPSS
0.15%
5.2th percentile
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_bridge | <= 16.0.5 | — |
| adobe | bridge | < 15.1.7 | 15.1.7 |
| adobe | bridge | >= 16.0 < 16.0.6 | 16.0.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user.
ghsa_unreviewed·2026-07-28
CVE-2026-48391 [HIGH] CWE-426 Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user.
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
VulDB
Adobe Bridge untrusted search path
vuldb·2026-07-28·CVSS 8.2
CVE-2026-48391 [HIGH] Adobe Bridge untrusted search path
A vulnerability, which was classified as critical, has been found in Adobe Bridge. The impacted element is an unknown function. The manipulation leads to untrusted search path.
This vulnerability is documented as CVE-2026-48391. The attack needs to be performed locally. There is not any exploit available.
No detection rules found.
No public exploits indexed.
2026-07-28
Published