Description
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write (CWE‑787) that allows a malicious file to overwrite memory, which can lead to arbitrary code execution when that file is opened by a user of Adobe Audition. The primary consequence is execution of arbitrary code in the context of the current user. The specific impact on confidentiality, integrity, and availability is not explicitly stated, but such code execution could potentially allow compromise of those aspects.

Affected Systems

Adobe Audition is the affected product. Specific vendor and product names are Adobe:Audition. No version information is provided in the data, so it is unclear which releases contain the flaw; administrators should assume all publicly released versions could be at risk until a vendor statement is available.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation requires the victim to open a malicious file, which means the attack can be triggered only when the user interacts with the file. That is the only reported attack vector.

Generated by OpenCVE AI on July 31, 2026 at 05:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Adobe Audition update that addresses the out-of-bounds write flaw.
  • Avoid opening audio files from untrusted or unknown sources until a patch is applied.
  • Use application isolation or sandboxing for Audition to limit the impact if an attacker succeeds in exploiting the vulnerability.

Generated by OpenCVE AI on July 31, 2026 at 05:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe audition
Vendors & Products Adobe
Adobe audition

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Audition | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T03:59:32.975Z

Reserved: 2026-05-20T15:50:31.364Z

Link: CVE-2026-47967

cve-icon Vulnrichment

Updated: 2026-07-14T18:14:35.011Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses