Junglewise Threat Intelligence

CVE-2026-21313: Adobe Audition out-of-bounds read in memory access

CVE-2026-21313 · Severity: medium · CVSS 5.5 · Published 2026-02-10

Technologies: Adobe Audition. Vendors: Adobe.

Executive brief

Adobe Audition, a professional audio editing application, contains an out-of-bounds read vulnerability that could allow attackers to access sensitive information stored in memory. The flaw requires a user to open a malicious file, making it a user-interaction-dependent attack. Successful exploitation could result in disclosure of sensitive data such as credentials or project information.

Technical details

This is an out-of-bounds read vulnerability in Adobe Audition versions 25.3 and earlier. The vulnerability allows an attacker to read memory beyond the intended boundaries of a buffer, potentially exposing sensitive data. The attack requires user interaction—a victim must open a crafted malicious file to trigger the vulnerability. No network connectivity or elevated privileges are needed. An attacker can leverage this to disclose sensitive information residing in application memory. A patch is expected from Adobe; users should update to versions later than 25.3 when available.

Affected products

  • Adobe Audition 25.3 and earlier

Timeline

  • 2026-02-10: disclosed: CVE-2026-21313 published

References

Related threats