
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27299 is an Improper Input Validation vulnerability in Adobe Framemaker that enables arbitrary file system read. Adobe Framemaker versions 2022.8 and earlier are affected; the vulnerability was disclosed on April 14, 2026, and patched in version 2022.9. Exploitation requires user interaction — a victim must open a malicious file crafted by the attacker. The CVSS v3.1 base score is 6.3 (Medium), with a changed scope and high confidentiality impact (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-20 (Improper Input Validation), where Adobe Framemaker fails to adequately validate input when processing specially crafted files, allowing an attacker to trigger arbitrary file system read operations. The attack vector is local, requiring no privileges but necessitating that a victim open a malicious document. The changed scope in the CVSS vector indicates that the impact extends beyond the vulnerable component itself, potentially exposing files accessible to the Framemaker process. No public technical write-ups or proof-of-concept code have been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated local attacker to read arbitrary files on the victim's system, resulting in a high confidentiality impact with no effect on integrity or availability. Sensitive data stored on disk — such as credentials, configuration files, or proprietary documents — could be exposed to the attacker. The changed scope suggests that files outside the Framemaker application's own context may be accessible, broadening the potential data exposure risk (Adobe Advisory).
.fm or other Framemaker-format files received via email or downloaded from untrusted sources; temporary files created by Framemaker in unusual directories containing contents of sensitive system files.%APPDATA%, C:\Windows\System32\, /etc/passwd) by the Framemaker process.FrameMaker.exe) accessing or reading files unrelated to the opened document, as observed via process monitoring tools such as Sysinternals Process Monitor.Adobe has released a patch in Adobe Framemaker version 2022.9, which addresses this vulnerability. Users should update to version 2022.9 or later immediately via the Adobe update mechanism or by downloading the update from Adobe's official site. As a workaround prior to patching, users should avoid opening Framemaker files received from untrusted or unknown sources, particularly those delivered via email or downloaded from the internet (Adobe Advisory).
The Center for Internet Security (CIS) published an advisory noting multiple vulnerabilities in Adobe products patched in April 2026, including this issue, flagging potential for arbitrary code execution across the Adobe product suite (CIS Advisory). No significant independent researcher commentary or notable social media discussion has been identified for this specific CVE, consistent with its medium severity rating and lack of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."