---
id: CVE-2026-76196
title: >-
  Photoshop Mobile is affected by a Session Fixation vulnerability that could
  result in privilege escalation
summary: >-
  Photoshop Mobile is affected by a Session Fixation vulnerability that could
  result in privilege escalation. An attacker could leverage this vulnerability
  to gain access to sensitive resources. Exploit depends on conditions beyond
  the att…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-384
vendor: adobe
product: photoshop_mobile
affected:
  - photoshop_mobile < 1.7.0.2302
patched:
  - photoshop_mobile 1.7.0.2302
published: '2026-09-08'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:56:50.440'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76196'
references:
  - url: 'https://helpx.adobe.com/security/products/photoshop/apsb26-136.html'
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T04:27:04.178571Z'
ingestedAt: '2026-09-08T19:08:49.627Z'
epss: 0.002
epssPercentile: 0.10103
---

## Overview

Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.

## Affected

- `photoshop_mobile < 1.7.0.2302`

## Remediation

Upgrade past the affected range:

- `photoshop_mobile 1.7.0.2302`
