Description
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Audition is vulnerable to an out‑of‑bounds write that occurs while parsing a specially crafted media file. The flaw allows an attacker to corrupt memory during file decoding, which can lead to arbitrary code execution in the user’s context. This is a classic type of buffer overflow defect identified as CWE‑787.

Affected Systems

Adobe Audition is affected. Because no specific version range is provided in the CNA data, every currently installed release of Audition should be considered vulnerable until an update is applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.8, indicating high severity. EPSS is below 1 %, so active exploitation is unlikely but not impossible. The issue is not listed in CISA’s KEV catalogue, suggesting no widespread attacks have been observed. Exploitation requires the victim to open a malicious file, making it a user‑interactive local file exploit that can compromise systems only when the software is running.

Generated by OpenCVE AI on August 3, 2026 at 03:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Audition update that includes the out‑of‑bounds write fix.
  • Restrict or quarantine unknown or untrusted media files by configuring file‑type filters and using a safe‑list policy for Audition.
  • Implement application whitelisting or sandboxing to contain any code that may execute if a malicious file is opened.

Generated by OpenCVE AI on August 3, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe audition
Vendors & Products Adobe
Adobe audition

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Audition | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:37:10.812Z

Reserved: 2026-05-21T15:28:38.136Z

Link: CVE-2026-48309

cve-icon Vulnrichment

Updated: 2026-07-15T10:37:05.720Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:30:13Z

Weaknesses