CVE-2026-48346: Animate | Untrusted Search Path (CWE-426)
Published Jul 14, 2026
·Updated
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected Software
5 affected components
Adobe Animate
All of the following
Any of the following
Adobe Animate>=23.0.0<23.0.16
Adobe Animate>=24.0.0<24.0.14
Any of the following
Apple macOS
Microsoft Windows
Event History
Jul 14, 2026
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48346?
CVE-2026-48346 has a high severity rating of 7.9.
2
What impact does CVE-2026-48346 have?
CVE-2026-48346 can result in arbitrary code execution in the context of the current user.
3
How do I fix CVE-2026-48346?
To mitigate CVE-2026-48346, users should ensure they only open files from trusted sources and apply any available software updates.
4
What user interaction is required for exploiting CVE-2026-48346?
Exploitation of CVE-2026-48346 requires the victim to open a malicious file.
5
Does CVE-2026-48346 affect system security?
Yes, CVE-2026-48346 poses a significant security risk as it allows arbitrary code execution.