← Vulnerability feed

Vulnerability record · CVE-2026-48344 · published 14 July 2026

CVE-2026-48344: Adobe creative cloud desktop application toctou race condition vulnerability

Adobe · Creative Cloud Desktop Application

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

7.8 CVSS 3.1 High EPSS 0.17% · top 94.2% CWE-367 · TOCTOU race condition
7.8CVSS 3.1 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
28 Aug 2026Last modified by NVD

Description

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-48344 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-9682Adobe creative cloud desktop application link following vulnerabilityAdobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to a…EPSS 4.3%9.8CVE-2020-9670Adobe creative cloud desktop application link following vulnerabilityAdobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to p…EPSS 3.6%9.8CVE-2020-9671Adobe creative cloud desktop application incorrect permission assignment vulnerabilityAdobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead…EPSS 4.0%7.8CVE-2026-48272Adobe creative cloud desktop application uncontrolled search path element vulnerabilityCreative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context …EPSS 0.23%7.8CVE-2021-43019Adobe creative cloud desktop application incorrect permission assignment vulnerabilityAdobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe servi…EPSS 2.2%7.8CVE-2021-28547Adobe creative cloud desktop application improper input validation vulnerabilityAdobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a n…EPSS 0.52%7.8CVE-2021-28594Adobe creative cloud desktop application uncontrolled search path element vulnerabilityAdobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability. An u…EPSS 2.7%7.8CVE-2021-21069Adobe creative cloud desktop application improper input validation vulnerabilityAdobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerability that could allow an atta…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2026-48344), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.