VYPR
High severity8.2NVD Advisory· Published Jul 28, 2026· Updated Aug 3, 2026

CVE-2026-48391

CVE-2026-48391

Description

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Affected products

2
  • Adobe Inc./Bridge2 versions
    cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:*range: <15.1.7
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

2