CVE-2026-27291: InDesign Desktop | Out-of-bounds Write (CWE-787)
Published Apr 14, 2026
·Updated
InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
3 affected components
Adobe InDesign Desktop=20.5.2, <=21.2
Adobe InDesign<20.5.3
Adobe InDesign>=21.0<21.3
Event History
Apr 14, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-27291?
The severity of CVE-2026-27291 is high due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2026-27291?
To fix CVE-2026-27291, update Adobe InDesign Desktop to version 21.3 or later.
3
What versions of InDesign Desktop are affected by CVE-2026-27291?
CVE-2026-27291 affects Adobe InDesign Desktop versions 20.5.2 and 21.2 and earlier.
4
What type of vulnerability is CVE-2026-27291?
CVE-2026-27291 is an out-of-bounds write vulnerability classified under CWE-787.
5
What is required for the exploitation of CVE-2026-27291?
Exploitation of CVE-2026-27291 requires user interaction to trigger the vulnerability.