Out-of-Bounds Write Vulnerability in Adobe DNG SDK
CVE-2026-27258

5.5MEDIUM

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
14 April 2026

What is CVE-2026-27258?

The DNG SDK from Adobe is susceptible to an out-of-bounds write vulnerability in versions 1.7.1 2502 and earlier. This flaw can be exploited to corrupt memory, resulting in application instability or denial-of-service. Exploitation requires user interaction, as the victim needs to open a specially crafted malicious file, which can trigger the undesired behavior and lead to potential application crashes.

Affected Version(s)

DNG SDK 0 <= 1.7.1 2502

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.