CVE-2026-48346 – Adobe Animate 2023
“A single malicious file could turn routine creative work into a system compromise.”
Adobe Animate 2023 contains six high-severity vulnerabilities that could result in arbitrary code execution in the current user’s context. The flaws include OS command injection, incorrect authorization, path traversal, and an untrusted search path. Most require a victim to open a malicious file, while CVE-2026-48349 does not require user interaction but depends on conditions beyond the attacker’s control.
CVE-2026-48345 has a CVSS score of 8.2, High severity. CVE-2026-48349 has a CVSS score of 8.1, High severity. CVE-2026-48350 has a CVSS score of 8.6, High severity. CVE-2026-48346 has a CVSS score of 7.9, High severity. CVE-2026-48347 has a CVSS score of 7.7, High severity. CVE-2026-48348 has a CVSS score of 7.7, High severity.
Key Details
- Affected Product
- Adobe Animate
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- Required
- CWE Classification
- CWE-426