{"id":"CVE-2026-80159","title":"Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation","summary":"Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions bey…","severity":"medium","cvss":4,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-426"],"vendor":"adobe","product":"acrobat","affected":["acrobat >= 24.001.20604, < 24.001.30429","acrobat_dc >= 15.008.20082, < 26.002.21901","acrobat_reader_dc >= 15.008.20082, < 26.002.21901"],"patched":["acrobat 24.001.30429","acrobat_dc 26.002.21901","acrobat_reader_dc 26.002.21901"],"published":"2026-09-08","updated":"2026-09-10","sourceUpdated":"2026-09-10T21:17:47.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80159","references":[{"url":"https://helpx.adobe.com/security/products/acrobat/apsb26-141.html","label":"psirt@adobe.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T20:41:03.546777Z"},"epss":0.00115,"epssPercentile":0.01771,"ingestedAt":"2026-09-08T21:11:12.369Z","slug":"CVE-2026-80159","body":"## Overview\n\nAcrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.\n\n## Affected\n\n- `acrobat >= 24.001.20604, < 24.001.30429`\n- `acrobat_dc >= 15.008.20082, < 26.002.21901`\n- `acrobat_reader_dc >= 15.008.20082, < 26.002.21901`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `acrobat 24.001.30429`\n- `acrobat_dc 26.002.21901`\n- `acrobat_reader_dc 26.002.21901`","depth":"sunlit","depthScore":22,"depthScoreParts":{"impact":22,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}