7.8
CVE-2026-48272
- EPSS 0.14%
- Veröffentlicht 14.07.2026 20:21:16
- Zuletzt bearbeitet 17.07.2026 03:24:18
- CVE-Watchlists
- Unerledigt
Creative Cloud Desktop | Uncontrolled Search Path Element (CWE-427)
Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Creative Cloud Desktop Application Version <= 6.9.1.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.035 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Adobe | 7.8 | 1.1 | 6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-427 Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
https://helpx.adobe.com/security/products/creative-cloud/apsb26-77.html