CVE-2026-76196 HIGH

CVE-2026-76196: Photoshop Mobile | Session Fixation (CWE-384)

Vendor Adobe
Product Photoshop Android
Weakness CWE-384 · Session fixation
Published September 8, 2026
Last update September 9, 2026

CVSS base score

7.4/10
Attack vector Local
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.

Key dates

02Disclosure timeline

September 8, 2026 CVE published
September 9, 2026 Record updated