Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.
History

Wed, 26 Aug 2026 17:30:00 +0000


Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Photoshop Installer
Vendors & Products Adobe
Adobe adobe Photoshop Installer

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.
Title Photoshop Installer | CWE-427: Uncontrolled Search Path Element
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2026-07-28T17:46:26.236Z

Updated: 2026-08-26T16:28:35.442Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48388

cve-icon Vulnrichment

Updated: 2026-08-26T16:28:35.442Z

cve-icon NVD

Status : Modified

Published: 2026-07-28T18:17:20.887

Modified: 2026-08-26T17:17:02.150

Link: CVE-2026-48388

cve-icon Redhat

No data.