---
id: CVE-2026-27299
title: >-
  Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input
  Validation vulnerability that could lead to arbitrary file system read
summary: >-
  Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input
  Validation vulnerability that could lead to arbitrary file system read. An
  attacker could leverage this vulnerability to access sensitive files or data
  on the…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'
cwe:
  - CWE-20
vendor: adobe
product: framemaker
affected:
  - framemaker < 2022.9
patched:
  - framemaker 2022.9
published: '2026-04-14'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-27299'
references:
  - url: 'https://helpx.adobe.com/security/products/framemaker/apsb26-36.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00155
epssPercentile: 0.05045
ingestedAt: '2026-07-26T10:11:59.807Z'
---

## Overview

Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to access sensitive files or data on the system. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `framemaker < 2022.9`

## Remediation

Upgrade past the affected range:

- `framemaker 2022.9`
