Description
Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Media Encoder is vulnerable to an out‑of‑bounds read that enables an attacker to access memory that was not intended to be visible outside the application, consistent with CWE‑125. This flaw can expose sensitive data that resides in memory during the file‑processing routine, potentially leaking confidential information to the attacker.

Affected Systems

Adobe Media Encoder is the sole affected product. The CNA lists Adobe as the vendor, but the advisory does not specify which releases are impacted, so any unpatched installation is potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate risk level. An EPSS score of less than 1% suggests that large‑scale exploitation is unlikely, yet an attacker could target specific users. The vulnerability is not listed in CISA KEV. Exploitation requires the victim to interact with a malicious media file, so the attack vector is file‑based and user‑initiated.

Generated by OpenCVE AI on July 31, 2026 at 05:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the Adobe update that addresses this vulnerability as soon as it is available.
  • Limit the opening of media files to trusted users or only allow digitally signed files to be processed by Media Encoder.
  • Run Adobe Media Encoder within a sandboxed or restricted environment to contain any unexpected memory access violations.

Generated by OpenCVE AI on July 31, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe media Encoder
Vendors & Products Adobe
Adobe media Encoder

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Media Encoder | Out-of-bounds Read (CWE-125)
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Media Encoder
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T14:29:35.569Z

Reserved: 2026-05-20T15:50:31.366Z

Link: CVE-2026-47979

cve-icon Vulnrichment

Updated: 2026-07-15T14:29:29.374Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:03Z

Weaknesses