Out-of-Bounds Read Vulnerability in Adobe DNG SDK
CVE-2026-47934

5.5MEDIUM

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-47934?

The DNG SDK versions 1.7.1 2536 and earlier have a significant out-of-bounds read vulnerability that can be exploited to disclose sensitive memory information. This security flaw requires user interaction, as an attacker must coax the victim into opening a specially crafted malicious file. Once activated, this vulnerability opens avenues for unauthorized access to potentially sensitive data, heightening security risks for users.

Affected Version(s)

DNG SDK 0 <= 1.7.1 2536

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.