Junglewise Threat Intelligence

CVE-2026-34627: Adobe InDesign heap overflow in file parsing

CVE-2026-34627 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Adobe InDesign. Vendors: Adobe.

Executive brief

Adobe InDesign, a professional desktop publishing software, is vulnerable to a security flaw when processing specially crafted files. If a user opens a malicious document, an attacker could gain the ability to run unauthorized commands or software on the victim's computer. This could lead to the theft of sensitive data, full system compromise, or disruption of business operations.

Technical details

A heap-based buffer overflow (CWE-122) exists in Adobe InDesign Desktop versions 20.5.2, 21.2, and earlier. The vulnerability is triggered when the application fails to properly validate input while parsing a malicious file, leading to memory corruption. An attacker can exploit this by convincing a user to open a specially crafted document, potentially resulting in arbitrary code execution in the context of the current user. The attack vector is local (AV:L) and requires user interaction (UI:R). Adobe has addressed this in newer versions (20.5.3 and 21.3).

Affected products

  • Adobe InDesign Desktop 20.5.2, 21.2 and earlier

Timeline

  • 2026-04-14: advisory: Initial advisory published by Adobe and NVD
  • 2026-04-14: disclosed

References

Related threats