PT-2026-32703 · Adobe · Indesign

Jann Horn

·

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2026-27291

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InDesign Desktop versions 20.5.2 and 21.2 and earlier
Description An out-of-bounds write occurs when a program writes data past the end of the intended buffer. This issue could result in arbitrary code execution in the context of the current user and requires user interaction, specifically the opening of a malicious file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-05398
CVE-2026-27291

Affected Products

Indesign