CVE-2026-34631 is an out-of-bounds write vulnerability affecting Adobe InCopy versions 20.5.2, 21.2 and earlier that could enable arbitrary code execution within the current user's context. The flaw requires user interaction, as victims must open a malicious file to trigger the vulnerability. This represents a local attack vector with no special privileges required and low attack complexity. The vulnerability carries a HIGH CVSS severity rating of 7.8, with high impacts across confidentiality, integrity, and availability. The attack vector is local, and successful exploitation could allow an attacker to execute arbitrary code with the privileges of the affected user. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on security hotlists. The extremely low EPSS score of 0.00034 indicates minimal real-world exploitation probability at this time. However, organizations using affected InCopy versions should prioritize patching to prevent potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.5.3CPE matchmatch criteria | cpe:2.3:a:adobe:incopy:*:*:*:*:*:*:*:* | ||
>= 21.0, < 21.3CPE matchmatch criteria | cpe:2.3:a:adobe:incopy:*:*:*:*:*:*:*:* | ||
>= 0, <= 21.2CPE match | cpe:2.3:a:adobe:incopy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.