Description
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write condition exists in Adobe Audition that can be triggered by opening a crafted file, allowing an attacker to overwrite memory and inject malicious code. The flaw is a classic buffer overflow identified as CWE‑787, leading to arbitrary code execution in the victim’s user context. This can compromise confidentiality, integrity, or availability of the affected system if the attacker successfully runs code with user privileges.

Affected Systems

Affected products are versions of Adobe Audition. No specific version information is provided in the advisory, meaning all releases of Audition remain susceptible until a patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1 % shows the likelihood of exploitation in the wild is very low at present. The vulnerability is not cataloged in CISA’s KEV list. The exploit requires user interaction to open a malicious media file, implying the attack vector is local file-based. If exploited, the attacker could execute code with the same privileges as the user, enabling data exfiltration or malware deployment.

Generated by OpenCVE AI on July 31, 2026 at 05:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe Audition security patch released in the APSB26‑71 advisory or upgrade to the latest Audition version that contains the fix.
  • Avoid opening unfamiliar or untrusted media files in Adobe Audition.
  • Keep Adobe Audition current by regularly installing updates from Adobe or subscribing to the Adobe Update service.

Generated by OpenCVE AI on July 31, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe audition
Vendors & Products Adobe
Adobe audition

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Audition | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:36:57.211Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48365

cve-icon Vulnrichment

Updated: 2026-07-15T10:36:52.639Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses