
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34702 is a Stack-based Buffer Overflow vulnerability (CWE-121) in Adobe InDesign Desktop that could allow arbitrary code execution in the context of the current user. It affects InDesign Desktop versions 21.3 and earlier (in the 21.x branch) and versions 20.5.3 and earlier (in the 20.x branch) on both Windows and macOS. Adobe disclosed and patched this vulnerability on June 9, 2026, as part of security bulletin APSB26-58. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), where a buffer allocated on the stack can be overwritten due to insufficient bounds checking when processing malicious file input. An attacker crafts a specially malformed InDesign file that, when opened by a victim, triggers the overflow and overwrites adjacent stack memory, potentially redirecting execution flow to attacker-controlled code. The attack vector is local (the malicious file must be delivered and opened on the victim's machine), requires no privileges, but does require user interaction — specifically, the victim must open the malicious file. No public proof-of-concept exploit code has been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the logged-in InDesign user, resulting in high confidentiality, integrity, and availability impact within the user's security context. An attacker could read sensitive files accessible to the user, modify or delete data, or crash the application. While the scope is unchanged (no privilege escalation beyond the current user context), the attack could serve as an initial foothold for further lateral movement if the compromised user has elevated permissions on the system (Adobe Advisory, GitHub Advisory).
cmd.exe, powershell.exe, /bin/bash, curl, wget) following the opening of an InDesign file.Adobe has released patched versions addressing this vulnerability: users on the 21.x branch should update to InDesign Desktop 21.4 or later, and users on the 20.x branch should update to version 20.5.4 or later. Updates are available through the Adobe Creative Cloud desktop application or via the Adobe Security Bulletin APSB26-58. As a temporary workaround until patching is possible, users should avoid opening InDesign files received from untrusted or unknown sources, and disable file preview features where available (Adobe Advisory).
Adobe addressed this vulnerability as part of its June 2026 Patch Tuesday-aligned security release, which covered multiple products. Security aggregators including BeyondMachines and Fortress SRM noted the June 2026 Adobe patch batch in their threat and security update summaries. The CISA Vulnerability Bulletin SB26-166 referenced the vulnerability as part of its weekly roundup. No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability tracking and aggregation (Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."