Description
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write flaw in Adobe Audition permits an attacker to execute arbitrary code in the context of the user who opens a malicious file. The weakness results in a potential loss of confidentiality, integrity, and availability of the victim’s system due to the ability to run code with the user’s privileges.

Affected Systems

All installations of Adobe Audition may be affected, as the advisory does not list a specific product or version range. Any user who has not applied the latest Adobe update should verify whether their product contains the fix referenced in the Adobe security bulletin and plan to update accordingly.

Risk and Exploitability

The CVSS score of 7.8 denotes high severity, while the EPSS score of less than 1% indicates that exploitation is not common yet but remains possible. Because the flaw requires the victim to open a malicious file, social engineering or deceptive attachments represent the likely attack vector. The vulnerability is not listed in the CISA KEV catalog, but administrators should treat it as a high‑risk issue and prioritize patch deployment.

Generated by OpenCVE AI on July 31, 2026 at 05:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Adobe Audition security update to eliminate the out‑of‑bounds write flaw.
  • Configure Audition to reject or prompt for unknown file types before opening, reducing the chance of accidentally loading malicious content.
  • Educate users to avoid opening unsolicited or suspicious files that could contain crafted Audition files, reinforcing safe attachment handling practices.

Generated by OpenCVE AI on July 31, 2026 at 05:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe audition
Vendors & Products Adobe
Adobe audition

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Audition | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T03:59:35.315Z

Reserved: 2026-05-20T15:50:31.365Z

Link: CVE-2026-47968

cve-icon Vulnrichment

Updated: 2026-07-14T19:41:12.966Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses