PT-2026-32948 · Adobe · Framemaker
Jann Horn
·
Published
2026-04-14
·
Updated
2026-04-15
·
CVE-2026-27299
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Framemaker versions prior to 2022.9
Description
Improper Input Validation allows arbitrary file system read, which could enable an attacker to access sensitive files or data on the system. Exploitation requires user interaction, specifically that a victim opens a malicious file.
Recommendations
Update to a version newer than 2022.8.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Framemaker