Description
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-04-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Adobe InDesign Desktop versions 20.5.2, 21.2 and earlier contain a heap‑based buffer overflow that can lead to arbitrary code execution within the context of the user who opens a malicious file. The vulnerability stems from an improperly bounded heap allocation and is classified as CWE‑122.

Affected Systems

The affected product is Adobe InDesign Desktop on Windows and macOS, specifically versions 20.5.2, 21.2, and earlier releases of the application.

Risk and Exploitability

The CVSS base score of 7.8 marks this as a high‑severity issue, while an EPSS score of less than 1 % indicates a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a single user interaction: the victim must open a crafted InDesign file, which can be delivered via phishing or other social engineering. Once the file is opened, arbitrary code with the victim’s privileges, presenting a serious risk if malicious documents are circulated.

Generated by OpenCVE AI on September 21, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Adobe InDesign Desktop update that addresses CVE‑2026‑27238.
  • If a patch is not yet available, restrict users from opening untrusted InDesign files and provide guidance on avoiding unknown sources.
  • Deploy file integrity monitoring or anti‑malware solutions to detect and block malicious InDesign files before they are opened.

Generated by OpenCVE AI on September 21, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 16 Sep 2026 18:30:00 +0000


Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed. InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
References

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Title InDesign Desktop | Heap-based Buffer Overflow (CWE-122) Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Thu, 16 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe indesign
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:indesign:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe indesign
Apple
Apple macos
Microsoft
Microsoft windows

Wed, 15 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe indesign Desktop
Vendors & Products Adobe
Adobe indesign Desktop

Tue, 14 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 17:00:00 +0000

Type Values Removed Values Added
Description InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Indesign Indesign Desktop
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-16T17:23:35.954Z

Reserved: 2026-02-18T22:02:41.382Z

Link: CVE-2026-27238

cve-icon Vulnrichment

Updated: 2026-04-14T19:40:03.277Z

cve-icon NVD

Status : Modified

Published: 2026-04-14T17:16:47.717

Modified: 2026-09-16T18:17:08.797

Link: CVE-2026-27238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T09:30:13Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow