CVE-2026-27290: Adobe Framemaker | Untrusted Search Path (CWE-426)
Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27290?
CVE-2026-27290 is rated as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2026-27290?
To mitigate CVE-2026-27290, users should update to the latest version of Adobe FrameMaker that addresses this vulnerability.
What versions of Adobe FrameMaker are affected by CVE-2026-27290?
Adobe FrameMaker versions 2022.8 and earlier are vulnerable to CVE-2026-27290.
What type of vulnerability is CVE-2026-27290?
CVE-2026-27290 is classified as an Untrusted Search Path vulnerability (CWE-426).
What could an attacker potentially do with CVE-2026-27290?
An attacker exploiting CVE-2026-27290 could execute arbitrary code in the context of the current user.