CVE-2026-27299: Adobe Framemaker | Improper Input Validation (CWE-20)
Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to access sensitive files or data on the system. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27299?
CVE-2026-27299 is considered a critical vulnerability due to its potential for arbitrary file system read access.
How do I fix CVE-2026-27299?
To fix CVE-2026-27299, update Adobe FrameMaker to the latest version released after 2022.8.
What versions of Adobe FrameMaker are affected by CVE-2026-27299?
CVE-2026-27299 affects Adobe FrameMaker versions 2022.8 and earlier.
What type of vulnerability is CVE-2026-27299?
CVE-2026-27299 is classified as an Improper Input Validation vulnerability.
What could an attacker achieve by exploiting CVE-2026-27299?
An attacker exploiting CVE-2026-27299 could gain unauthorized access to sensitive files or data on the system.