Executive brief
Adobe Audition, a professional audio workstation used for sound editing and mixing, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands or access sensitive data with the same permissions as the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Audition versions 26.0 and 25.6.4 and earlier. The flaw is triggered when the application improperly handles memory while processing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious file, leading to memory corruption and potential arbitrary code execution in the context of the current user. The vulnerability is addressed in versions 26.3 and 25.6.6. The attack vector is local, requiring user interaction (UI:R) but no prior privileges (PR:N).
Affected products
- Adobe Audition <= 26.0, <= 25.6.4
Timeline
- 2026-07-14: advisory: Adobe published security bulletin APSB26-71
- 2026-07-14: disclosed: CVE-2026-47968 published to NVD