
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34706 is an out-of-bounds write vulnerability in Adobe InCopy that could result in arbitrary code execution in the context of the current user. It affects InCopy versions 21.3 and earlier (in the 21.x branch) and versions 20.5.3 and earlier (in the 20.x branch) on both Windows and macOS. Adobe disclosed and patched the vulnerability on June 9, 2026, as part of its June 2026 security update cycle. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the boundaries of an allocated buffer during file parsing. Exploitation requires a local attack vector — an attacker must craft a malicious InCopy file and socially engineer a victim into opening it, at which point the out-of-bounds write is triggered during file processing. No privileges are required on the part of the attacker, but user interaction is mandatory. No public technical write-up or proof-of-concept code has been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Adobe InCopy, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive files accessible to the user, modify or delete data, or cause the application to crash. Since code executes in the context of the current user, the blast radius is limited to that user's permissions, though it could serve as a foothold for further lateral movement in environments where InCopy users have elevated privileges (Adobe Advisory, GitHub Advisory).
.icml or .incd) that triggers an out-of-bounds write during parsing by embedding malformed data structures that overflow an internal buffer.cmd.exe, powershell.exe, bash, curl, wget) following the opening of an InCopy file.%APPDATA%, /tmp) shortly after opening an InCopy document; dropped executables or scripts not associated with normal InCopy operation.Adobe has released patched versions addressing this vulnerability: InCopy 21.4 (for the 21.x branch) and InCopy 20.5.4 (for the 20.x branch) on Windows and macOS. Users should update immediately via the Creative Cloud desktop application or Adobe's update mechanism. As a workaround prior to patching, users should avoid opening InCopy files from untrusted or unknown sources, and organizations may consider restricting file execution policies or using application allowlisting (Adobe Advisory).
Adobe's June 2026 patch release covering multiple products, including InCopy, was noted in security community roundups. Fortress SRM included this vulnerability in their June 2026 threat and security update summary, and CISA referenced it in their weekly vulnerability bulletin (SB26-166). No significant independent researcher commentary or social media discussion specific to this CVE has been identified beyond standard aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."