---
id: CVE-2026-21276
title: >-
  InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access
  of Uninitialized Pointer vulnerability that could result in arbitrary code
  execution in the context of the current user
summary: >-
  InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access
  of Uninitialized Pointer vulnerability that could result in arbitrary code
  execution in the context of the current user. Exploitation of this issue
  requires use…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-824
vendor: adobe
product: indesign
affected:
  - indesign < 20.5.1
  - 'indesign >= 21.0, < 21.1'
patched:
  - indesign 21.1
published: '2026-01-13'
updated: '2026-08-27'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21276'
references:
  - url: 'https://helpx.adobe.com/security/products/indesign/apsb26-02.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00247
epssPercentile: 0.14163
ingestedAt: '2026-08-27T21:08:14.474Z'
---

## Overview

InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `indesign < 20.5.1`
- `indesign >= 21.0, < 21.1`

## Remediation

Upgrade past the affected range:

- `indesign 21.1`
