---
id: CVE-2026-92180
title: >-
  pdfforge PDF Architect activation-service Update Service Uncontrolled Search
  Path Element Local Privilege Escalation Vulnerability
summary: >-
  pdfforge PDF Architect activation-service Update Service Uncontrolled Search
  Path Element Local Privilege Escalation Vulnerability. This vulnerability
  allows local attackers to escalate privileges on affected installations of
  pdfforge PD…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-427
vendor: pdfforge
product: PDF Architect
affected:
  - pdf_architect 9.1.90.23122
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:26:50.280'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92180'
references:
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-26-615/'
    label: zdi-disclosures@trendmicro.com
tags:
  - nvd
  - cve.org
zeroDay: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T19:22:58.050488Z'
ingestedAt: '2026-09-15T18:41:59.184Z'
epss: 0.00195
epssPercentile: 0.08156
---

## Overview

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
