
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48293 is an out-of-bounds write vulnerability (CWE-787) in Adobe InDesign Desktop that can result in arbitrary code execution in the context of the current user. It affects InDesign Desktop versions 21.3 and earlier (in the 21.x branch) and versions 20.5.3 and earlier (in the 20.x branch) on both Windows and macOS. Adobe disclosed and patched the vulnerability on June 9, 2026, as part of security bulletin APSB26-58. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the boundaries of an allocated buffer during the processing of a crafted InDesign file. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a specially crafted malicious file. Successful exploitation triggers the out-of-bounds write condition, which can corrupt memory in a way that allows an attacker to redirect execution flow and achieve arbitrary code execution (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Adobe InDesign, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker could read sensitive files accessible to the user, modify data, or cause the application to crash. The scope is limited to the current user's context, but on systems where InDesign users have elevated privileges, the impact could be more significant (Adobe Advisory, GitHub Advisory).
.indd or related format) that contains malformed data designed to trigger an out-of-bounds write when parsed by the InDesign file processing engine..indd or related files received from unknown sources.cmd.exe, powershell.exe, bash, curl, or other network utilities) shortly after opening a document.Adobe has released patched versions addressing this vulnerability: InDesign Desktop 21.4 (for the 21.x branch) and 20.5.4 (for the 20.x branch) on both Windows and macOS. Users should update to these versions immediately via the Creative Cloud desktop application or Adobe's update mechanism. As a precautionary measure, users should avoid opening InDesign files from untrusted or unknown sources, and organizations may consider implementing application sandboxing for InDesign processes where feasible (Adobe Advisory).
The vulnerability was noted in Adobe's June 2026 patch cycle, which addressed multiple products. Security aggregators including Tenable (Nessus plugin 320133), CISA's vulnerability bulletin (SB26-166), and Fortress SRM's June 2026 threat update referenced the issue as part of broader Adobe patch coverage. No significant independent researcher commentary or social media discussion specific to this CVE has been identified beyond standard vulnerability tracking and aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."