Skip to content
AdobeCVE-2026-76196

Adobe Photoshop Android: session fixation

High7.4CVE-2026-76196 · Published Sep 8, 2026 · updated Sep 9, 2026

Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.

Adobe advisory

Affected versions

PackageAffectedFixed in
Photoshop Android
Product
<= 1.6.0.2294No fix yet
<= 1.6.0.2299No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-384

More Adobe advisories

All Adobe
Advisory
Adobe Acrobat 2024: heap buffer overflow
Medium5.5Sep 8
Adobe Acrobat 2024: prototype pollution
High8.2Sep 8
Adobe Acrobat 2024: improper authorization
High8.8Sep 8
Adobe Acrobat 2024: improper authorization
Medium6.3Sep 8
Adobe Acrobat 2024: resource exhaustion
Medium5.5Sep 8
Adobe Acrobat 2024: use after free
High7.8Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.