CVE-2026-48388
Adobe · Photoshop Installer
The Adobe Photoshop Installer is affected by an uncontrolled search path element vulnerability that may lead to arbitrary code execution for the current user.
Executive summary
A vulnerability in the Adobe Photoshop Installer enables local attackers to execute arbitrary code through an uncontrolled search path.
Vulnerability
This vulnerability is categorized as an uncontrolled search path element (CWE-427), which allows an attacker to influence the application search path for executables or libraries. Exploitation allows for arbitrary code execution in the context of the user running the installer.
Business impact
Exploitation of this vulnerability during the installation process could lead to the installation of malicious software or total compromise of the user account. The CVSS score of 8.6 indicates a high risk, particularly during administrative or system-wide software deployment phases.
Remediation
Immediate Action: Consult the official Adobe security advisory for specific patched versions and follow the recommended installation procedures.
Proactive Monitoring: Audit installation logs and ensure that software installations are only performed from trusted, verified sources.
Compensating Controls: Use application control policies to prevent the execution of untrusted binaries from temporary or writable directories.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
While specific version details are currently unclear, administrators should monitor Adobe security channels for the release of fixed installers. Ensure that all software installation processes are conducted in secure environments to mitigate the risk of path manipulation.