Description
InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-22
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Update Application
AI Analysis

Impact

This vulnerability is a NULL Pointer Dereference in Adobe InDesign Desktop that causes the application to crash. The result is a denial‑of‑service condition that prevents the program from running normally. It arises when a specific memory reference is null and the software attempts to read or write through it, in line with CWE‑476. The impact is limited to application availability and does not provide attacker control over the host system.

Affected Systems

Adobe InDesign Desktop is affected. No specific version details are provided, so all installations of Adobe InDesign Desktop are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate level of severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low or unclear public exploitation likelihood. Exploitation requires user interaction: a victim must open a malicious file crafted by the attacker. The attack vector is therefore local or user‑initiated rather than remote.

Generated by OpenCVE AI on September 22, 2026 at 19:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure all customers have installed the latest Adobe InDesign Desktop release containing the fix for this issue.
  • Archive or delete any suspicious or unknown InDesign files and avoid opening files from untrusted sources.
  • Configure file‑type warnings or sandboxing to prevent automatic opening of InDesign documents from unverified sources.

Generated by OpenCVE AI on September 22, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe indesign Desktop
Vendors & Products Adobe
Adobe indesign Desktop

Tue, 22 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title InDesign Desktop | NULL Pointer Dereference (CWE-476)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Adobe Indesign Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T19:07:31.669Z

Reserved: 2026-08-19T11:07:21.444Z

Link: CVE-2026-76192

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:47.637

Modified: 2026-09-22T19:23:57.800

Link: CVE-2026-76192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:30:14Z

Weaknesses