Junglewise Threat Intelligence

CVE-2026-27299: Adobe FrameMaker improper input validation in file parsing

CVE-2026-27299 · Severity: medium · CVSS 6.3 · Published 2026-04-14

Technologies: Microsoft Windows, Adobe Framemaker. Vendors: Microsoft, Adobe.

Executive brief

Adobe FrameMaker, a professional document authoring and publishing solution, is affected by a security flaw that allows unauthorized access to local files. An attacker could trick a user into opening a specially crafted document, which then allows the attacker to read sensitive information from the victim's computer. This could lead to the theft of private data or corporate intellectual property stored on the affected system.

Technical details

An improper input validation vulnerability (CWE-20) exists in Adobe FrameMaker versions 2022.8 and earlier. The flaw occurs when the application fails to properly validate input within a document file, which can be exploited to perform an arbitrary file system read. The attack vector is local, requiring a victim to manually open a maliciously crafted file provided by the attacker. Successful exploitation allows the attacker to bypass security boundaries and read sensitive files from the local file system with the permissions of the current user. Adobe has addressed this issue in version 2022.9.

Affected products

  • Adobe FrameMaker 2022.8 and earlier

Timeline

  • 2026-04-14: advisory: Initial disclosure by Adobe and NVD publication
  • 2026-04-14: patched: Adobe released version 2022.9 to address the issue

References

Related threats