Description
Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-09-08
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Acrobat Reader contains an untrusted search path flaw that permits an attacker with high privileges to elevate their access level. The vulnerability requires the victim to open a malicious file, and it relies on conditions beyond the attacker’s direct control, meaning successful exploitation is not guaranteed without user interaction.

Affected Systems

Affected products include Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat, with no documented version restrictions beyond the listed vendors.

Risk and Exploitability

The CVSS score of 4 indicates a moderate impact, and the EPSS score is not available, so exploitation likelihood is uncertain. The vulnerability is not listed in CISA’s KEV catalog. An attacker must already possess elevated privileges and convince a user to open a malicious document before the path selection flaw can be abused, reducing the overall threat but still enabling privilege escalation.

Generated by OpenCVE AI on September 9, 2026 at 09:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe Acrobat Reader update that addresses the untrusted search path flaw immediately.
  • Restrict the execution of Acrobat binaries to trusted directories or disable the untrusted search path on regulated systems.
  • Limit user privileges on accounts that run Acrobat to the least level necessary for their duties.
  • Educate users to avoid opening files from untrusted sources and verify file integrity before execution.

Generated by OpenCVE AI on September 9, 2026 at 09:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Vendors & Products Adobe acrobat 2024

Thu, 10 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Acrobat Reader | Untrusted Search Path (CWE-426)
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-17T19:04:32.184Z

Reserved: 2026-08-25T20:51:11.639Z

Link: CVE-2026-80159

cve-icon Vulnrichment

Updated: 2026-09-10T20:55:41.692Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:42.980

Modified: 2026-09-10T21:17:47.627

Link: CVE-2026-80159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T19:15:14Z

Weaknesses