CVE-2026-84395: Server-Side Request Forgery (SSRF) (CWE-918) in Adobe Premiere
Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
AI Analysis
Technical Summary
CVE-2026-84395 is a Server-Side Request Forgery (SSRF) vulnerability in Adobe Premiere Pro that allows an attacker to induce the server to make unintended requests. Exploitation does not require user interaction and can result in privilege escalation. The vulnerability affects versions up to 26.3.2 and 25.6.5. The scope is changed, meaning the vulnerability impacts components beyond the originally vulnerable part. The CVSS v3.1 score is 7.1, indicating a high severity with low attack complexity and no required privileges or user interaction.
Potential Impact
Successful exploitation of this SSRF vulnerability can lead to privilege escalation within the affected Adobe Premiere Pro environment. This increases the attacker's capabilities beyond initial access, potentially allowing unauthorized actions at a higher privilege level. The vulnerability does not impact confidentiality but has a high impact on integrity. Availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix information is provided, users should monitor Adobe's security advisories for updates. Until a fix is available, consider restricting network access for the affected application to limit SSRF exploitation potential.
CVE-2026-84395: Server-Side Request Forgery (SSRF) (CWE-918) in Adobe Premiere
Description
Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS v3.1
Score 7.1high
Affected software
Adobe
Premiere
Adobe
Premiere
pkg:github/adobe/premiereRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-84395 is a Server-Side Request Forgery (SSRF) vulnerability in Adobe Premiere Pro that allows an attacker to induce the server to make unintended requests. Exploitation does not require user interaction and can result in privilege escalation. The vulnerability affects versions up to 26.3.2 and 25.6.5. The scope is changed, meaning the vulnerability impacts components beyond the originally vulnerable part. The CVSS v3.1 score is 7.1, indicating a high severity with low attack complexity and no required privileges or user interaction.
Potential Impact
Successful exploitation of this SSRF vulnerability can lead to privilege escalation within the affected Adobe Premiere Pro environment. This increases the attacker's capabilities beyond initial access, potentially allowing unauthorized actions at a higher privilege level. The vulnerability does not impact confidentiality but has a high impact on integrity. Availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or fix information is provided, users should monitor Adobe's security advisories for updates. Until a fix is available, consider restricting network access for the affected application to limit SSRF exploitation potential.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- adobe
- Date Reserved
- 2026-09-01T16:49:48.598Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab2d481f7a7c54106a364ce
Added to database: 09/22/2026, 19:18:25 UTC
Last enriched: 09/22/2026, 19:32:50 UTC
Last updated: 09/22/2026, 19:49:04 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.