CVE-2026-75990
massIncorrect Authorization in Adobe Illustrator allows code execution via malicious files
Adobe Illustrator contains an incorrect authorization flaw (CWE-863) that fails to properly enforce access checks, which could result in arbitrary code execution in the context of the current user. Exploitation requires user interaction: a victim must open a malicious file (e.g., an untrusted Illustrator document) for the attacker's code to run, and the local attack vector means the attacker cannot trigger it remotely on their own. The 'scope changed' designation in the CVSS vector indicates the flaw can cross a security boundary, letting an attacker execute code beyond the initially affected component with the victim user's privileges. All Illustrator users who open files from untrusted or unsolicited sources are potentially affected; the available data does not specify affected version ranges. There is currently no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days (10th percentile).
What to do: Update Illustrator to the patched build listed in Adobe's security bulletin (fixed version not specified in the available data) via the Creative Cloud desktop app and verify the installed version against the advisory. Until patched, avoid opening Illustrator files from untrusted or unsolicited sources, since exploitation requires user interaction to open a malicious file.
| Adobe Illustrator | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.