CVE-2026-76191 PUBLISHED

Animate | Improper Control of Generation of Code ('Code Injection') (CWE-94)

Assigner: adobe
Reserved: 19.08.2026 Published: 08.09.2026 Updated: 09.09.2026

Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS Score: 8.2

Product Status

Vendor Adobe
Product Adobe Animate 2023
Versions Default: unaffected
  • affected from 0 to 23.0.16 (incl.)
  • Version 23.0.17 is unaffected
Vendor Adobe
Product Adobe Animate 2024
Versions Default: unaffected
  • affected from 0 to 24.0.14 (incl.)
  • Version 24.0.15 is unaffected

References

Problem Types

  • Improper Control of Generation of Code ('Code Injection') (CWE-94) CWE