Description
InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-22
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Application Denial of Service
Action: Update Software
AI Analysis

Impact

A NULL Pointer Dereference in Adobe InDesign Desktop causes the application to crash when processing a maliciously crafted file. The failure manifests as a denial‑of‑service for the user, preventing normal use of InDesign until the program is restarted. The weakness is identified as CWE‑476.

Affected Systems

Adobe InDesign Desktop is affected; no specific versions are disclosed in the available data.

Risk and Exploitability

The CVSS base score of 5.5 indicates a moderate severity and suggests that exploitation is not trivial but can affect availability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, implying that no widespread active exploitation campaigns are known. Exploitation requires a victim to open a malicious file, so user interaction is the attack vector, reducing the likelihood of automated attacks but still presenting a risk in environments where users handle untrusted documents.

Generated by OpenCVE AI on September 22, 2026 at 19:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe InDesign update that fixes the NULL Pointer Dereference issue
  • Configure InDesign or the operating environment to block automatic opening of unknown files or use a sandboxed execution context
  • Train users to verify the source of files before opening them

Generated by OpenCVE AI on September 22, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title InDesign Desktop | NULL Pointer Dereference (CWE-476)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-22T18:33:25.676Z

Reserved: 2026-09-01T16:49:48.598Z

Link: CVE-2026-84396

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T19:16:54.390

Modified: 2026-09-22T19:23:57.800

Link: CVE-2026-84396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:30:14Z

Weaknesses