Out-of-Bounds Read Vulnerability in InCopy by Adobe
CVE-2026-27287

7.8HIGH

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
14 April 2026

What is CVE-2026-27287?

InCopy versions 20.5.2, 21.2, and earlier are subject to an out-of-bounds read vulnerability when processing specially crafted files. This security flaw allows attackers to read beyond the limits of allocated memory structures. Successful exploitation requires user interaction as the victim must open a malicious file, potentially enabling an attacker to execute unauthorized code within the context of the current user. It is crucial for users of affected versions to apply patches or updates to mitigate this vulnerability.

Affected Version(s)

InCopy 0 <= 21.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.