CVE-2026-81997Medium· 6.3▾ SunlitAcrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploita…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
acrobat >= 24.0.0, < 24.001.30429acrobat_dc >= 15.008.20082, < 26.002.21901acrobat_reader_dc >= 15.008.20082, < 26.002.21901Upgrade past the affected range:
acrobat 24.001.30429acrobat_dc 26.002.21901acrobat_reader_dc 26.002.21901Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81996High· 8.8Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation
CVE-2026-79908High· 7.8Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-81975High· 7.8Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-79907High· 7.8Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-79909High· 7.8Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user
CVE-2026-79910Medium· 5.5Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory