---
id: CVE-2026-79904
title: >-
  Photoshop Mobile is affected by an Improper Limitation of a Pathname to a
  Restricted Directory ('Path Traversal') vulnerability that could result in a
  Security feature bypass
summary: >-
  Photoshop Mobile is affected by an Improper Limitation of a Pathname to a
  Restricted Directory ('Path Traversal') vulnerability that could result in a
  Security feature bypass. A low-privileged attacker could leverage this
  vulnerability t…
severity: medium
cvss: 5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H'
cwe:
  - CWE-22
vendor: adobe
product: photoshop_mobile
affected:
  - photoshop_mobile < 1.7.0.2302
patched:
  - photoshop_mobile 1.7.0.2302
published: '2026-09-08'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:56:29.457'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79904'
references:
  - url: 'https://helpx.adobe.com/security/products/photoshop/apsb26-136.html'
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T18:20:28.042420Z'
ingestedAt: '2026-09-08T19:08:49.630Z'
epss: 0.00195
epssPercentile: 0.08155
---

## Overview

Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `photoshop_mobile < 1.7.0.2302`

## Remediation

Upgrade past the affected range:

- `photoshop_mobile 1.7.0.2302`
