
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21278 is an Out-of-bounds Read vulnerability (CWE-125) in Adobe InDesign Desktop that can lead to memory exposure and disclosure of sensitive information. It affects InDesign Desktop versions 21.0 and 19.5.5 and earlier (specifically, all versions before 20.5.1 in the 19.x branch, and versions 21.0 up to but excluding 21.1). The vulnerability was disclosed by Adobe on January 13, 2026, with an initial NVD analysis completed on January 14, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium), assigned by Adobe Systems Incorporated (Adobe Advisory, NVD).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), a memory safety flaw where the application reads data beyond the allocated buffer boundary. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a specially crafted malicious file within InDesign Desktop. When the malicious file is parsed, the out-of-bounds read condition is triggered, potentially exposing contents of process memory to the attacker. No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory, NVD).
Successful exploitation results in a high confidentiality impact — an attacker can read sensitive information from the InDesign process memory — while integrity and availability are unaffected. The vulnerability is constrained to the local attack surface, meaning an attacker must deliver a malicious InDesign file to a victim and convince them to open it. The primary risk is memory disclosure, which could expose credentials, document content, or other sensitive data resident in the application's memory space at the time of exploitation (Adobe Advisory, NVD).
.indd or related format) designed to trigger an out-of-bounds read during file parsing by exploiting improper buffer boundary checks in InDesign Desktop..indd, .idml, or other InDesign-format files received via email or downloaded from untrusted sources.InDesign.exe on Windows or Adobe InDesign on macOS) crashing or exhibiting abnormal behavior (e.g., access violation errors) when opening specific files.Adobe has released patched versions to address this vulnerability: users should update InDesign Desktop to version 20.5.1 (for the 19.x/20.x branch) or version 21.1 (for the 21.x branch). As a workaround, users should avoid opening InDesign files received from untrusted or unknown sources. Organizations can implement application controls or file-type filtering to restrict which files users are permitted to open. Updating to the patched version is the recommended and definitive remediation (Adobe Advisory).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Adobe products, including CVE-2026-21278, that could allow for arbitrary code execution or information disclosure (CIS Advisory). The vulnerability was also covered in the Zero Day Initiative's January 2026 Security Update Review. No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability tracking and aggregation sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."