CVE-2026-76199
massSearch-Path Hijack in Adobe Photoshop Desktop Allows Code Execution via Malicious File
CVE-2026-76199 is an uncontrolled search path element flaw (CWE-427) in Adobe Photoshop Desktop, a class of issue similar to DLL search-order hijacking where the application loads code from an attacker-influenced location. To trigger it, a victim must open a malicious file while the vulnerable desktop application is installed, allowing the attacker to have arbitrary code executed in the context of the current user; the 'scope changed' flag indicates the impact can extend beyond the vulnerable component's own security scope, which drives the elevated 8.6 High CVSS score. Successful exploitation gives the attacker code execution with the victim's privileges, enabling follow-on actions such as deploying malware or accessing data available to that user. All users running Adobe Photoshop Desktop are potentially affected, though the provided data does not specify exact version ranges. There is no evidence of active exploitation: EPSS is low (0.2% probability within 30 days), the flaw is not in CISA's KEV catalog, and no public proof-of-concept is known.
What to do: Update Photoshop Desktop to the fixed release listed in Adobe's security bulletin for this CVE, as the provided data does not include version numbers. Until patching, avoid opening image or project files from untrusted sources, since exploitation requires a victim to open a malicious file. Because exploitation is local and user-triggered, organizations should also review endpoint controls that limit execution of downloaded files in user-writable directories.
| Adobe Photoshop Desktop | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
- Vendors
- adobe
- Products
- photoshop
- Weakness
- CWE-427
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.