CVE-2026-76199

Adobe Security Bulletin APSB26-130 — Photoshop

Beschreibung

Photoshop Desktop ist von einer Schwachstelle des Typs Unkontrollierter Suchpfad-Elemente betroffen, die zur willkürlichen Codeausführung im Kontext des aktuellen Benutzers führen könnte. Ein Angreifer könnte diese Schwachstelle ausnutzen, um beliebigen Code auszuführen. Die Ausnutzung dieses Problems erfordert eine Interaktion durch den Benutzer, da das Opfer eine bösartige Datei öffnen muss. Der Geltungsbereich wurde geändert.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.6
Quelle: nvd-v3
11.4 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.2 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-08 20:18 UTC
CWE-427

Weakness-Klassen (CWE)

  • CWE-427Base

    Uncontrolled Search Path Element

    The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-09 10:21 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-76199","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…{"id":"CVE-2026-76199","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  2. CVE Modified2026-09-09 05:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-76199","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-08 20:18 UTC· psirt@adobe.com
    • Description: Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
    • CVSS V3.1: AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
    • CWE: CWE-427
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/76xxx/CVE-2026-76199.json">CVE-2026-76199</a>

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Adobe

    Photoshop2025 <26.11.7

  • Adobe

    Photoshop2026 <27.7

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-76199