Out-of-Bounds Read Vulnerability in DNG SDK by Adobe
CVE-2026-47927

5.5MEDIUM

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-47927?

DNG SDK versions 1.7.1 2536 and earlier are susceptible to an out-of-bounds read vulnerability, which can be exploited to disclose sensitive information from memory. Attackers need the victim to open a specially crafted file for exploitation to occur, potentially leading to unintended data exposure. This vulnerability underscores the importance of securing file handling processes and ensuring that users are aware of file origins before opening them.

Affected Version(s)

DNG SDK 0 <= 1.7.1 2536

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.