CVE-2026-48391: Bridge | Untrusted Search Path (CWE-426)
Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48391?
CVE-2026-48391 has a severity rating of 8.2, categorized as high.
What is the risk associated with CVE-2026-48391?
The risk associated with CVE-2026-48391 is assessed at 66.
What type of vulnerability is CVE-2026-48391?
CVE-2026-48391 is an Untrusted Search Path vulnerability (CWE-426) affecting Bridge.
How do I fix CVE-2026-48391?
To fix CVE-2026-48391, ensure to update to the latest version of Bridge as recommended by the vendor.
Who can exploit CVE-2026-48391?
A low-privileged attacker can exploit CVE-2026-48391 with user interaction to execute arbitrary code.