Executive brief
Adobe DNG SDK is a software development kit used by applications to handle Digital Negative (DNG) image files. A security flaw in this library could allow an attacker to take control of a user's computer if the user is tricked into opening a specially crafted, malicious image file. This could lead to unauthorized access to data or the installation of malicious software.
Technical details
A stack-based buffer overflow (CWE-121) exists in Adobe DNG SDK versions 1.7.1 2536 and earlier. The vulnerability is triggered when the library parses a specially crafted DNG file, leading to memory corruption. An attacker can exploit this to execute arbitrary code in the context of the current user. This is a local attack vector that requires user interaction, specifically the opening of a malicious file by a victim. Adobe has addressed this in security bulletin APSB26-67.
Affected products
- Adobe DNG SDK 1.7.1 2536 and earlier
Timeline
- 2026-07-20: advisory: Adobe published security bulletin APSB26-67
- 2026-07-20: disclosed: CVE-2026-48389 published to NVD