Improper Input Validation in Adobe Framemaker Could Lead to File Exposure
CVE-2026-27299

6.3MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
14 April 2026

What is CVE-2026-27299?

Adobe Framemaker versions 2022.8 and prior are susceptible to an improper input validation issue, which could permit unauthorized access to sensitive files on the file system. An attacker must entice a victim into opening a specially crafted malicious file to exploit this vulnerability. This scenario underscores the importance of user vigilance in file handling, particularly when dealing with documents from unknown or untrusted sources.

Affected Version(s)

Adobe Framemaker 0 <= 2022.8

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.