Out-of-Bounds Read Vulnerability in DNG SDK by Adobe
CVE-2026-34616

5.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
27 August 2026

What is CVE-2026-34616?

The DNG SDK, specifically versions 1.7.1 2502 and earlier, contain an out-of-bounds read vulnerability. This flaw allows unauthorized access to sensitive information in memory when a victim interacts with a specially crafted malicious file. An attacker can exploit this issue, leading to potential disclosure of critical data, thus highlighting the importance of keeping software updated and exercising caution when handling unknown files.

Affected Version(s)

Adobe DNG Software Development Kit (SDK) 0 <= 1.7.1.2502

Adobe DNG Software Development Kit (SDK) 0 <= 1.7.1.2502

Adobe DNG Software Development Kit (SDK) 1.7.1.2536

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.