CVE-2026-48390

High8.2Published on July 28, 2026

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVSS score8.2 / 10CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Weakness type (CWE)CWE-863
Vendorsadobe

Affected products

VendorsProductVersions
adobebridge< 15.1.7

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database