CVE-2026-76199: Photoshop Desktop | Uncontrolled Search Path Element (CWE-427)
Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must persuade a victim to open a malicious file. Successful exploitation can then execute arbitrary code in the context of the current user.
Who is affected if exploitation succeeds?
The code runs with the privileges of the user who opens the malicious file. The vulnerability has changed scope and can affect confidentiality, integrity, and availability beyond that initial security authority.
Can this be exploited without user interaction?
No. The provided information states that exploitation requires user interaction, specifically opening a malicious file.