CVE-2026-81994
massPrototype Pollution in Adobe Acrobat Reader Enables Arbitrary File Read
Adobe Acrobat Reader contains an improperly controlled modification of object prototype attributes ('prototype pollution') vulnerability (CWE-1321) that can allow an attacker to perform an arbitrary file system read. The flaw is triggered when a victim opens a malicious file, making user interaction a requirement for exploitation. A successful attack could let the attacker access sensitive files and directories outside the intended access scope; the changed scope in the CVSS vector indicates the impact extends beyond the vulnerable component, with high confidentiality and integrity impact. Users of Adobe Acrobat Reader across desktop deployments are potentially affected. As of now there is no evidence of exploitation, no known public proof-of-concept, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days (23rd percentile).
What to do: Update Acrobat Reader to the fixed release identified in Adobe's security bulletin for this CVE, as specific affected/fixed version numbers were not provided in the source data. Until patching is complete, exercise caution with PDF files from untrusted sources since exploitation requires a victim to open a malicious file. Monitor Adobe advisories and threat feeds for any emergence of public exploits given the high severity rating.
| Adobe Acrobat Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
- Vendors
- adobe
- Products
- acrobat, acrobat dc, acrobat reader dc
- Weakness
- CWE-1321
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.