CVE-2026-27299 MEDIUM

CVE-2026-27299: Adobe Framemaker | Improper Input Validation (CWE-20)

Vendor Adobe
Product Adobe Framemaker
Weakness CWE-20 · Input validation
Published April 14, 2026
Last update April 15, 2026

CVSS base score

6.3/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to access sensitive files or data on the system. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Key dates

02Disclosure timeline

April 14, 2026 CVE published
April 15, 2026 Record updated