Junglewise Threat Intelligence

CVE-2026-34708: Adobe InCopy stack-based buffer overflow

CVE-2026-34708 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe InCopy. Vendors: Adobe.

Executive brief

Adobe InCopy, a professional writing and editing software, is affected by a security flaw that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands or software with the same permissions as the logged-in user, potentially leading to data theft or full system compromise.

Technical details

A stack-based buffer overflow (CWE-121) exists in Adobe InCopy versions 21.3, 20.5.3 and earlier. The vulnerability is triggered when the application improperly handles memory while parsing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Adobe has addressed this in security bulletin APSB26-59.

Affected products

  • Adobe InCopy 21.3, 20.5.3 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats