Description
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-09-08
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Check for Update
AI Analysis

Impact

Acrobat Reader is affected by a prototype‑pollution flaw that allows malicious code in a PDF to modify the prototype of JavaScript objects. This can lead to arbitrary file system reads, enabling an attacker to access sensitive files and directories outside the intended access scope. The impact is primarily confidentiality loss through unauthorized disclosure of files the user should not see, with scope expanded to any files the current user can read.

Affected Systems

The susceptible products include Adobe Acrobat 2024, Adobe Acrobat Reader, and Adobe Acrobat. The CVE does not list specific revision numbers, so installations of these products prior to any official remediation are potentially vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.2, indicating high severity. EPSS data is not available, and it is not listed in the CISA KEV catalog. Exploitation requires user interaction; the victim must open a malicious PDF file to trigger the prototype pollution. Because scope is changed, the attacker can read files owned by the current user and any other files the user has permissions for, creating a significant risk of data exposure.

Generated by OpenCVE AI on September 9, 2026 at 09:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Avoid opening PDF files from untrusted emails or websites to reduce the chance of exposure with a malicious document.
  • Keep the PDF reader updated and apply any vendor‑issued updates promptly when they become available.
  • If the application offers security settings, temporarily disable or restrict JavaScript execution in PDF files to limit the attack surface.

Generated by OpenCVE AI on September 9, 2026 at 09:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe acrobat 2024
Adobe acrobat Reader
Vendors & Products Adobe acrobat 2024
Adobe acrobat Reader

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:*
cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe
Adobe acrobat
Adobe acrobat Dc
Adobe acrobat Reader Dc
Apple
Apple macos
Microsoft
Microsoft windows

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Acrobat Acrobat 2024 Acrobat Dc Acrobat Reader Acrobat Reader Dc
Apple Macos
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-09-10T14:59:14.097Z

Reserved: 2026-08-27T21:20:45.366Z

Link: CVE-2026-81994

cve-icon Vulnrichment

Updated: 2026-09-09T17:29:16.554Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T21:18:46.223

Modified: 2026-09-10T15:17:47.323

Link: CVE-2026-81994

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:30:14Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')