Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. Exploitation of this issue does not require user interaction.
References
| Link | Resource |
|---|---|
| https://helpx.adobe.com/security/products/framemaker/apsb26-36.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
15 Apr 2026, 18:32
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:* |
|
| References | () https://helpx.adobe.com/security/products/framemaker/apsb26-36.html - Vendor Advisory | |
| First Time |
Adobe
Adobe framemaker Microsoft Microsoft windows |
14 Apr 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-14 23:16
Updated : 2026-04-15 18:32
NVD link : CVE-2026-27290
Mitre link : CVE-2026-27290
CVE.ORG link : CVE-2026-27290
JSON object : View
Products Affected
adobe
- framemaker
microsoft
- windows
CWE
CWE-426
Untrusted Search Path
