ZeroHour

CVE-2026-76199

mass

Search-Path Hijack in Adobe Photoshop Desktop Allows Code Execution via Malicious File

CVSS 3.1
8.6 high
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-76199 is an uncontrolled search path element flaw (CWE-427) in Adobe Photoshop Desktop, a class of issue similar to DLL search-order hijacking where the application loads code from an attacker-influenced location. To trigger it, a victim must open a malicious file while the vulnerable desktop application is installed, allowing the attacker to have arbitrary code executed in the context of the current user; the 'scope changed' flag indicates the impact can extend beyond the vulnerable component's own security scope, which drives the elevated 8.6 High CVSS score. Successful exploitation gives the attacker code execution with the victim's privileges, enabling follow-on actions such as deploying malware or accessing data available to that user. All users running Adobe Photoshop Desktop are potentially affected, though the provided data does not specify exact version ranges. There is no evidence of active exploitation: EPSS is low (0.2% probability within 30 days), the flaw is not in CISA's KEV catalog, and no public proof-of-concept is known.

What to do: Update Photoshop Desktop to the fixed release listed in Adobe's security bulletin for this CVE, as the provided data does not include version numbers. Until patching, avoid opening image or project files from untrusted sources, since exploitation requires a victim to open a malicious file. Because exploitation is local and user-triggered, organizations should also review endpoint controls that limit execution of downloaded files in user-writable directories.

Affected
Adobe Photoshop Desktop
Estimated exposure
masstens of millions of desktop installations (Photoshop's Creative Cloud subscriber base) — Photoshop Desktop is one of the most widely deployed professional desktop applications and ships with Adobe Creative Cloud, whose subscriber base is reported in the tens of millions, so installed-user exposure is plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Vendors
adobe
Products
photoshop
Weakness
CWE-427
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.