CVE-2026-34702: InDesign Desktop | Stack-based Buffer Overflow (CWE-121)
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
InDesign Desktopfrom your environment.Uninstall or remove InDesign Desktop versions 21.3, 20.5.3 and earlier if the application is not required, until a vendor-provided fix is available.
- Compensating control
Prevent opening untrusted InDesign files (e.g., block .indd attachments at mail gateway, quarantine or scan incoming files) and restrict exchange of InDesign files from untrusted sources, since exploitation requires a victim to open a malicious file.
- Operational
Advise and train users to not open InDesign files from unknown or untrusted sources and to treat unexpected InDesign files as potentially malicious.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34702?
CVE-2026-34702 has a high severity rating of 7.8.
How do I fix CVE-2026-34702?
To fix CVE-2026-34702, you should update Adobe InDesign to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-34702?
CVE-2026-34702 is a stack-based buffer overflow vulnerability.
What can happen if CVE-2026-34702 is exploited?
Exploitation of CVE-2026-34702 could lead to arbitrary code execution in the context of the current user.
What is required for the exploitation of CVE-2026-34702?
Exploitation of CVE-2026-34702 requires user interaction, specifically opening a malicious file.