PT-2026-32940 · Adobe · Framemaker

Jann Horn

·

Published

2026-04-14

·

Updated

2026-04-15

·

CVE-2026-27290

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Framemaker versions 2022.8 and earlier
Description An Untrusted Search Path issue exists where the application uses a search path to locate critical resources such as programs. An attacker could modify this search path to point to a malicious program, which the application would then execute, potentially allowing arbitrary code execution in the context of the current user. This exploitation does not require user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Untrusted Search Path

Weakness Enumeration

Related Identifiers

BDU:2026-05407
CVE-2026-27290

Affected Products

Framemaker