CVE-2026-48349: Animate | Incorrect Authorization (CWE-863)
Published Jul 14, 2026
·Updated
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
5 affected components
Animate
All of the following
Any of the following
Adobe Animate>=23.0.0<23.0.16
Adobe Animate>=24.0.0<24.0.14
Any of the following
Apple macOS
Microsoft Windows
Event History
Jul 14, 2026
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48349?
CVE-2026-48349 has a severity rating of 8.1, indicating a high risk level.
2
What kind of vulnerability is CVE-2026-48349?
CVE-2026-48349 is classified as an Incorrect Authorization vulnerability.
3
What could happen if CVE-2026-48349 is exploited?
Exploitation of CVE-2026-48349 could result in arbitrary code execution in the context of the current user.
4
Does CVE-2026-48349 require user interaction for exploitation?
No, exploitation of CVE-2026-48349 does not require user interaction.
5
What affects the exploitability of CVE-2026-48349?
The exploitability of CVE-2026-48349 depends on conditions beyond the attacker's control.