Description
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information from memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-27
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an out‑of‑bounds read within the Adobe DNG SDK, allowing an attacker to read memory that should not be accessible. This can lead to disclosure of sensitive data that resides in the process memory, such as credentials or other confidential information. The vulnerability is identified by CWE‑125 and is limited to memory exposure, not execution of arbitrary code.

Affected Systems

Adobe’s DNG SDK, versions 1.7.1 2502 and older, are vulnerable. Any installation of these SDK releases that processes DNG files may be impacted.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a maliciously crafted DNG file, meaning user interaction is a prerequisite. While this limits automated attacks, the potential for sensitive data leakage remains a concern if users are tricked into opening such files.

Generated by OpenCVE AI on August 28, 2026 at 05:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Adobe DNG SDK to a patched release (at least version 1.7.1 2503 or later).
  • Configure the system to only open DNG files from trusted sources or enforce strict file‑type validation to prevent accidental execution of malicious files.
  • If a patch is unavailable, consider disabling DNG support in applications or employing application‑level sandboxing to isolate the SDK from untrusted input.

Generated by OpenCVE AI on August 28, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information from memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title DNG SDK | Out-of-bounds Read (CWE-125)
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:15:47.148Z

Reserved: 2026-03-30T17:30:36.489Z

Link: CVE-2026-34616

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:34.757

Modified: 2026-08-28T00:17:15.537

Link: CVE-2026-34616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:00:14Z

Weaknesses