CVE-2026-34632 Details
Description
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation of this issue required user interaction in that a victim must have been running the installer. Scope is changed.
A vulnerability has been identified in the Adobe Photoshop Installer, characterized as an Uncontrolled Search Path Element issue. This vulnerability could lead to arbitrary code execution within the context of the current user. It arises from the installer manipulating the search path to locate essential resources, potentially allowing unauthorized code to be executed. Exploitation of this vulnerability necessitated user interaction, as a user had to be actively running the installer.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2274 | CVE | ExploitThird Party Advisory |
| https://cwe.mitre.org/data/definitions/427.html | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe photoshop installer | 2.11.0.30 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | Modified Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | [email protected] |
| Jul 8, 2026 | Reanalysis | [email protected] |
| Jul 7, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | CVE Modified | CVE |
| Apr 15, 2026 | New CVE Received | [email protected] |