Junglewise Threat Intelligence

CVE-2026-21317: Adobe Audition out-of-bounds read in file parsing

CVE-2026-21317 · Severity: medium · CVSS 5.5 · Published 2026-02-10

Technologies: Adobe Audition. Vendors: Adobe.

Executive brief

Adobe Audition, a professional audio editing application, contains a memory reading vulnerability that occurs when processing malicious audio files. An attacker could craft a specially designed file that, when opened by a user, exposes sensitive data from the application's memory to the attacker. This could compromise confidential information such as passwords, encryption keys, or other sensitive data processed by the application.

Technical details

The vulnerability is an out-of-bounds read flaw in Audition's file parsing logic affecting versions 25.3 and earlier. When processing a malicious file, the application reads memory beyond intended boundaries, potentially exposing sensitive information. The attack requires user interaction—a victim must open a specially crafted file—making it a local, user-driven exploitation vector. An attacker can leverage this to disclose sensitive data stored in process memory. Adobe has addressed this issue in later versions.

Affected products

  • Adobe Audition 25.3 and earlier

Timeline

  • 2026-02-10: disclosed

References

Related threats