CVE-2026-48350 – Adobe Animate 2023

CVSS 8.6 IMPORTANT High with EoP or RCE – Expedited Deployment

“A single malicious file could turn routine creative work into a system compromise.”

Adobe Animate 2023 contains six high-severity vulnerabilities that could result in arbitrary code execution in the current user’s context. The flaws include OS command injection, incorrect authorization, path traversal, and an untrusted search path. Most require a victim to open a malicious file, while CVE-2026-48349 does not require user interaction but depends on conditions beyond the attacker’s control.

CVE-2026-48345 has a CVSS score of 8.2, High severity. CVE-2026-48349 has a CVSS score of 8.1, High severity. CVE-2026-48350 has a CVSS score of 8.6, High severity. CVE-2026-48346 has a CVSS score of 7.9, High severity. CVE-2026-48347 has a CVSS score of 7.7, High severity. CVE-2026-48348 has a CVSS score of 7.7, High severity.

Key Details

Affected Product
Adobe Animate
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-22
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.