Description
Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-04-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Execution of code in user context
Action: Immediate Patch
AI Analysis

Impact

Adobe Framemaker versions 2022.8 and earlier contain an out‑of‑bounds read vulnerability that can be triggered when the application parses a specially crafted file. The read past the end of an allocated memory structure can lead to execution of arbitrary code in the context of the user who opens the file. The primary impact is therefore the possibility of code execution with the user’s privileges, potentially allowing an attacker to compromise the host system. The vulnerability is a classic memory corruption flaw categorized as CWE‑125.

Affected Systems

Adobe Framemaker is the affected product. Versions 2022.8 and all earlier releases are susceptible to the flaw. Any installation of Adobe Framemaker published before the issuance of the Adobe Security Advisory for APSB26‑36 is considered insecure and should be updated. The advisory does not list newer releases as affected.

Risk and Exploitability

The base score assigned by the Common Vulnerability Scoring System is 7.8, indicating a high severity. The Exploit Prediction Scoring System score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires user interaction; a victim must open a malicious file for the vulnerability to be exercised. This limitation reduces the likelihood of widespread automated exploitation but still poses a significant threat in environments where users routinely handle untrusted documents. The vulnerability can be leveraged by an attacker who can deliver or trick a user into opening a crafted file, resulting in arbitrary code execution with the user’s rights.

Generated by OpenCVE AI on April 15, 2026 at 00:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Framemaker to a version newer than 2022.8 to eliminate the out-of-bounds read flaw
  • Configure Adobe Framemaker to automatically receive security updates, ensuring that the latest patches are applied promptly
  • Restrict the opening of unknown or suspicious file types, or implement strict file‑type validation, until the update is installed
  • Educate users to avoid opening unsolicited documents and scan files with anti‑malware before opening

Generated by OpenCVE AI on April 15, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Wed, 15 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe framemaker
Vendors & Products Adobe
Adobe framemaker

Wed, 15 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 23:15:00 +0000

Type Values Removed Values Added
Description Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Adobe Framemaker | Out-of-bounds Read (CWE-125)
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Framemaker
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-04-15T09:13:10.507Z

Reserved: 2026-02-18T22:02:41.396Z

Link: CVE-2026-27294

cve-icon Vulnrichment

Updated: 2026-04-15T09:07:18.527Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-14T23:16:26.303

Modified: 2026-04-15T18:14:55.687

Link: CVE-2026-27294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T14:53:45Z

Weaknesses