Junglewise Threat Intelligence

CVE-2026-47963: Adobe DNG SDK out-of-bounds read

CVE-2026-47963 · Severity: medium · CVSS 5.5 · Published 2026-06-16

Technologies: Adobe DNG SDK. Vendors: Adobe.

Executive brief

Adobe DNG SDK, a software tool used by developers to handle digital image files, contains a security flaw that could allow an attacker to access sensitive information. To exploit this, an attacker would need to trick a user into opening a specially crafted, malicious image file. Successful exploitation could lead to the unauthorized disclosure of private data stored in the computer's memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Adobe DNG SDK versions 1.7.1 2536 and earlier. The flaw occurs when the SDK processes specially crafted DNG files, allowing the application to read data past the end of the intended buffer. An attacker can exploit this by providing a malicious file to a user, which, when opened, could result in the disclosure of sensitive information from the process memory. The attack vector is local and requires user interaction (UI:R), with no prior authentication required.

Affected products

  • Adobe DNG SDK 1.7.1 2536 and earlier

Timeline

  • 2026-06-16: disclosed: Initial disclosure by Adobe
  • 2026-06-16: advisory: Adobe security bulletin APSB26-67 published

References

Related threats