#VU126370 Improper input validation in Adobe Framemaker - CVE-2026-27299

 

#VU126370 Improper input validation in Adobe Framemaker - CVE-2026-27299

Published: April 17, 2026


Vulnerability identifier: #VU126370
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-27299
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Adobe Framemaker
Software vendor:
Adobe

Description

The vulnerability allows a remote attacker to read arbitrary files.

The vulnerability exists due to improper input validation in Adobe FrameMaker when parsing input. A remote attacker can trick the victim into opening crafted content to read arbitrary files.

User interaction is required to open crafted content.


Remediation

Install security update from vendor's website.

External links