CVE-2026-75990: Illustrator | Incorrect Authorization (CWE-863)
Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must persuade a victim to open a malicious file. Exploitation then allows arbitrary code execution in the context of the current user.
Does successful exploitation require prior access or credentials?
No privileges are required before exploitation, but user interaction is required because the victim must open the malicious file.
What is the potential impact of a successful exploit?
A successful exploit can execute arbitrary code as the current user. The supplied vector indicates high impacts to confidentiality, integrity, and availability, with scope changed.