ZeroHour

CVE-2026-81994

mass

Prototype Pollution in Adobe Acrobat Reader Enables Arbitrary File Read

CVSS 3.1
6.3 medium
EPSS
<1%p23
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains an improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability (CWE-1321) that can allow an attacker to perform an arbitrary file system read. The flaw is triggered when a victim opens a malicious file, making user interaction a requirement for exploitation. A successful attack could let the attacker access sensitive files and directories outside the intended access scope; the changed scope in the CVSS vector indicates the impact extends beyond the vulnerable component, with high confidentiality and integrity impact. Users of Adobe Acrobat Reader across desktop deployments are potentially affected. As of now there is no evidence of exploitation, no known public proof-of-concept, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days (23rd percentile).

What to do: Update Acrobat Reader to the fixed release identified in Adobe's security bulletin for this CVE, as specific affected/fixed version numbers were not provided in the source data. Until patching is complete, exercise caution with PDF files from untrusted sources since exploitation requires a victim to open a malicious file. Monitor Adobe advisories and threat feeds for any emergence of public exploits given the high severity rating.

Affected
Adobe Acrobat Reader
Estimated exposure
masshundreds of millions of users (Acrobat Reader is the world's dominant PDF reader) — Adobe Acrobat Reader is the most widely deployed desktop PDF reader, with hundreds of millions of users per Adobe's published user figures, so the exposed population is plausibly in the hundreds of millions even though the flaw requires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-1321
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.