CVE-2026-47927
published 2026-06-16CVE-2026-47927: DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.17%
6.2th percentile
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | dng_sdk | <= 1.7.1 2536 | — |
| adobe | dng_software_development_kit | < 1.7.1.2611 | 1.7.1.2611 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe DNG SDK up to 1.7.1 2536 File out-of-bounds (apsb26-67)
vuldb·2026-06-16·CVSS 5.5
CVE-2026-47927 [MEDIUM] Adobe DNG SDK up to 1.7.1 2536 File out-of-bounds (apsb26-67)
A vulnerability categorized as problematic has been discovered in Adobe DNG SDK up to 1.7.1 2536. Affected by this issue is some unknown functionality of the component File Handler. Such manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-47927. Local access is required to approach this attack. No exploit exists.
GHSA
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.
ghsa_unreviewed·2026-06-16
CVE-2026-47927 [MEDIUM] CWE-125 DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published