Junglewise Threat Intelligence

CVE-2026-34629: Adobe InDesign heap overflow in file processing

CVE-2026-34629 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Adobe InDesign. Vendors: Adobe.

Executive brief

Adobe InDesign, a professional desktop publishing software, is vulnerable to a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could execute commands or access data with the same permissions as the logged-in user.

Technical details

A heap-based buffer overflow (CWE-122) exists in Adobe InDesign Desktop versions 20.5.2, 21.2, and earlier. The vulnerability is triggered when the application improperly handles memory allocation while processing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local with required user interaction (UI:R). Adobe has addressed this in newer versions (20.5.3 and 21.3).

Affected products

  • Adobe InDesign Desktop <= 20.5.2, <= 21.2

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory: Adobe released security bulletin APSB26-32

References

Related threats