CVE-2026-47934
published 2026-06-16CVE-2026-47934: DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.17%
6.1th percentile
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | dng_sdk | <= 1.7.1 2536 | — |
| adobe | dng_software_development_kit | < 1.7.1.2611 | 1.7.1.2611 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.
ghsa_unreviewed·2026-06-16
CVE-2026-47934 [MEDIUM] CWE-125 DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.
DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulDB
Adobe DNG SDK up to 1.7.1 2536 File out-of-bounds (apsb26-67)
vuldb·2026-06-16·CVSS 5.5
CVE-2026-47934 [MEDIUM] Adobe DNG SDK up to 1.7.1 2536 File out-of-bounds (apsb26-67)
A vulnerability identified as problematic has been detected in Adobe DNG SDK up to 1.7.1 2536. This affects an unknown part of the component File Handler. Performing a manipulation results in out-of-bounds read.
This vulnerability was named CVE-2026-47934. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published