Description
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an out-of-bounds write in Adobe Audition that can be abused to execute arbitrary code within the context of the current user. The flaw originates from improper memory bounds checking when processing audio files, allowing a crafted file to overwrite adjacent memory and overwrite control data. If exploited, the attacker could run arbitrary code, compromise data confidentiality, integrity, and availability for the affected user.

Affected Systems

Adobe Audition on all versions that have not received Adobe's security update. Specific affected versions are not listed in the advisory, so all installations prior to patching should be considered at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity of the risk. The EPSS score of less than 1% suggests that exploitation is considered unlikely in the current threat environment, and it is not listed in the CISA KEV catalog. Nevertheless, the flaw requires user interaction: a victim must open a malicious audio file, which is a relatively low barrier in contexts where users frequently handle untrusted audio files. The risk remains significant due to the high impact of code execution and the relative ease of file-based delivery.

Generated by OpenCVE AI on July 31, 2026 at 05:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Audition security update released by Adobe to address the out-of-bounds write flaw.
  • Restrict users from opening unknown audio files in Audition and employ file type verification or sandboxing when processing unfamiliar files.
  • Run Adobe Audition with standard user privileges and monitor for anomalous behavior to contain potential exploitation attempts.

Generated by OpenCVE AI on July 31, 2026 at 05:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe audition
Vendors & Products Adobe
Adobe audition

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Audition | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T03:59:36.836Z

Reserved: 2026-05-21T15:28:38.141Z

Link: CVE-2026-48368

cve-icon Vulnrichment

Updated: 2026-07-14T18:17:30.867Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses