PT-2026-7383 · Adobe · Indesign

Jann Horn

·

Published

2026-02-10

·

Updated

2026-02-10

·

CVE-2026-21332

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe InDesign versions 21.1 and earlier Adobe InDesign version 20.5.1 and earlier
Description The Adobe InDesign software contains a flaw related to reading beyond the boundaries of allocated memory. Successful exploitation of this issue could allow an attacker to disclose sensitive information stored in memory. Exploitation requires a user to open a specially crafted file.
Recommendations Update Adobe InDesign to a version later than 21.1. Update Adobe InDesign to a version later than 20.5.1.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2026-01926
CVE-2026-21332

Affected Products

Indesign