CVE Explorer
CVE-2026-27284
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"affected","product":"InDesign Desktop","vendor":"Adobe","versions":[{"lessThanOrEqual":"21.2","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6200019510db4b3f3e2c2e6cea4c515fbe1092bb6d65db4e32c209f97ab9caa9 · sha256:f2a771c856c0af7f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","availabilityRequirement":"NOT_DEFINED","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","confidentialityRequirement":"NOT_DEFINED","environmentalScore":7.8,"environmentalSeverity":"HIGH","exploitCodeMaturity":"NOT_DEFINED","integrityImpact":"HIGH","integrityRequirement":"NOT_DEFINED","modifiedAttackComplexity":"LOW","modifiedAttackVector":"LOCAL","modifiedAvailabilityImpact":"HIGH","modifiedConfidentialityImpact":"HIGH","modifiedIntegrityImpact":"HIGH","modifiedPrivilegesRequired":"NONE"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6200019510db4b3f3e2c2e6cea4c515fbe1092bb6d65db4e32c209f97ab9caa9 · sha256:f2a771c856c0af7f… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-125","description":"Out-of-bounds Read (CWE-125)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6200019510db4b3f3e2c2e6cea4c515fbe1092bb6d65db4e32c209f97ab9caa9 · sha256:f2a771c856c0af7f… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://helpx.adobe.com/security/products/indesign/apsb26-32.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6200019510db4b3f3e2c2e6cea4c515fbe1092bb6d65db4e32c209f97ab9caa9 · sha256:f2a771c856c0af7f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.