CVE-2026-48391

Adobe · Adobe Bridge

Adobe Bridge is vulnerable to an untrusted search path flaw that can lead to arbitrary code execution in the context of the current user.

Executive summary

An untrusted search path vulnerability in Adobe Bridge could allow a local attacker to execute arbitrary code with the privileges of the active user session.

Vulnerability

The application is affected by an untrusted search path vulnerability, which occurs when the software looks for resources in insecure locations. This allows a local attacker with low privileges to potentially execute arbitrary code, provided they can trick a user into interacting with a malicious file or path.

Business impact

Successful exploitation allows an attacker to execute code as the current user, potentially leading to data exfiltration or installation of persistent malware. With a CVSS score of 8.2, this high severity vulnerability poses a significant risk to workstations and creative environments where Adobe Bridge is frequently utilized.

Remediation

Immediate Action: Update Adobe Bridge to version 16.0.6 or 15.1.7 immediately to address the insecure search path implementation.

Proactive Monitoring: Review file system logs for unexpected execution of binaries from non-standard directories or unusual application startup patterns.

Compensating Controls: Implement endpoint protection solutions that restrict the ability of applications to execute files from user-writable directories.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Adobe Bridge users should apply the provided updates as soon as possible to neutralize this code execution risk. Maintaining updated software is the most effective way to prevent exploitation of this untrusted search path flaw.