Junglewise Threat Intelligence

CVE-2026-34703: Adobe InDesign NULL Pointer Dereference vulnerability

CVE-2026-34703 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Adobe InDesign Desktop. Vendors: Adobe.

Executive brief

Adobe InDesign, a professional desktop publishing software, is affected by a vulnerability that can cause the application to crash. An attacker could trick a user into opening a specially crafted file, leading to a loss of unsaved work and a disruption of business operations. This issue primarily impacts the availability of the software rather than the confidentiality of customer data.

Technical details

A NULL Pointer Dereference vulnerability (CWE-476) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The flaw is triggered when the application attempts to read or process a specifically crafted malicious file. An attacker can exploit this by distributing a malicious document that, when opened by a user, causes the application to crash (Denial of Service). The attack vector is local and requires user interaction (UI:R). No privilege escalation or data exfiltration is associated with this specific vulnerability. Adobe has addressed this in security bulletin APSB26-58.

Affected products

  • Adobe InDesign Desktop 21.3, 20.5.3 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats