Threat Advisory

Adobe Bridge Vulnerabilities Enable Document Access and Authority Elevation

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Adobe Bridge, which could allow attackers to execute arbitrary code or escalate privileges without user interaction. The flaws are caused by incorrect authorization, untrusted search path, path traversal, and out-of-bounds write vulnerabilities. The vulnerabilities affect Adobe Bridge deployments on Windows and Linux platforms.

CVE-2026-48395 (CVSS 8.6 — High): An untrusted search path vulnerability in Adobe Bridge, which could lead to arbitrary code execution.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Adobe Bridge, which could allow attackers to execute arbitrary code or escalate privileges without user interaction. The flaws are caused by incorrect authorization, untrusted search path, path traversal, and out-of-bounds write vulnerabilities. The vulnerabilities affect Adobe Bridge deployments on Windows and Linux platforms.

CVE-2026-48395 (CVSS 8.6 — High): An untrusted search path vulnerability in Adobe Bridge, which could lead to arbitrary code execution.[emaillocker id="1283"]

CVE-2026-48396 (CVSS 8.6 — High): This vulnerability is related to incorrect authorization and could allow privilege escalation, giving attackers higher privileges and access to sensitive areas of the system.

CVE-2026-48390 (CVSS 8.2 — High): This vulnerability is related to untrusted search path and could allow arbitrary code execution, potentially leading to system compromise.

CVE-2026-48391 (CVSS 8.2 — High): This vulnerability is related to path traversal and could allow arbitrary code execution, posing a risk to the system and data.

CVE-2026-48374 (CVSS 7.8 — High): This vulnerability is related to out-of-bounds write and could allow arbitrary code execution, potentially leading to system compromise.

CVE-2026-48392 (CVSS 7.8 — High): This vulnerability is related to out-of-bounds write and could allow arbitrary code execution, posing a risk to the system and data.

CVE-2026-48393 (CVSS 7.8 — High): An out-of-bounds write vulnerability in Adobe Bridge could allow attackers to execute arbitrary code through crafted input handling.

CVE-2026-48394 (CVSS 7.8 — High): An out-of-bounds write vulnerability in Adobe Bridge could allow attackers to execute arbitrary code in the context of the current user by exploiting a malicious file requiring user interaction.

RECOMMENDATIONS:

  • We recommend you to update Adobe Bridge to below version:
  • https://helpx.adobe.com/security/products/bridge/apsb26-89.html

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu