---
id: CVE-2026-81994
title: >-
  Acrobat Reader is affected by an Improperly Controlled Modification of Object
  Prototype Attributes ('Prototype Pollution') vulnerability that could lead to
  arbitrary file system read
summary: >-
  Acrobat Reader is affected by an Improperly Controlled Modification of Object
  Prototype Attributes ('Prototype Pollution') vulnerability that could lead to
  arbitrary file system read. An attacker could exploit this vulnerability to
  acces…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-1321
vendor: adobe
product: acrobat
affected:
  - 'acrobat >= 24.001.20604, < 24.001.30429'
  - 'acrobat_dc >= 15.008.20082, < 26.002.21901'
  - 'acrobat_reader_dc >= 15.008.20082, < 26.002.21901'
patched:
  - acrobat 24.001.30429
  - acrobat_dc 26.002.21901
  - acrobat_reader_dc 26.002.21901
published: '2026-09-08'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:17:47.323'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81994'
references:
  - url: 'https://helpx.adobe.com/security/products/acrobat/apsb26-141.html'
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T17:29:10.269154Z'
epss: 0.006
epssPercentile: 0.46493
ingestedAt: '2026-09-08T21:11:12.369Z'
---

## Overview

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

## Affected

- `acrobat >= 24.001.20604, < 24.001.30429`
- `acrobat_dc >= 15.008.20082, < 26.002.21901`
- `acrobat_reader_dc >= 15.008.20082, < 26.002.21901`

## Remediation

Upgrade past the affected range:

- `acrobat 24.001.30429`
- `acrobat_dc 26.002.21901`
- `acrobat_reader_dc 26.002.21901`
