CVE-2026-34699: InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34699?
The severity of CVE-2026-34699 is classified as high with a score of 7.8.
What components are affected by CVE-2026-34699?
CVE-2026-34699 affects Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier.
How do I fix CVE-2026-34699?
To fix CVE-2026-34699, users should update Adobe InDesign Desktop to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-34699?
CVE-2026-34699 is a heap-based buffer overflow vulnerability that can lead to arbitrary code execution.
What is required for exploitation of CVE-2026-34699?
Exploitation of CVE-2026-34699 requires user interaction, specifically opening a malicious file.