---
id: CVE-2026-47937
title: >-
  Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by
  an Uncontrolled Search Path Element vulnerability that could result in
  arbitrary code execution in the context of the current user
summary: >-
  Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by
  an Uncontrolled Search Path Element vulnerability that could result in
  arbitrary code execution in the context of the current user. An attacker with
  high priv…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-427
published: '2026-06-09'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47937'
references:
  - url: 'https://helpx.adobe.com/security/products/acrobat/apsb26-63.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00281
epssPercentile: 0.18237
ingestedAt: '2026-06-29T14:29:18.108Z'
---

## Overview

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
