CVE-2026-81996
massLocal Privilege Escalation via Incorrect Authorization in Adobe Acrobat Reader
CVE-2026-81996 is an incorrect authorization flaw (CWE-863) in Adobe Acrobat Reader that fails to properly enforce privilege boundaries, allowing a local attacker to escalate privileges. A low-privileged attacker with local access can trigger the flaw without any user interaction, per the CVSS vector (AV:L/AC:L/PR:L/UI:N) and the vendor description. Successful exploitation grants elevated access beyond the attacker's normal privileges, with high impact on confidentiality, integrity, and availability; the changed-scope rating indicates the escalation crosses a security boundary, meaning the attacker gains authority beyond the application's own context. Any user running the affected Acrobat Reader versions is exposed, although the attacker must first be able to execute code locally on the host. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation is documented, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.
What to do: Patch by upgrading Acrobat Reader to the fixed release identified in Adobe's security bulletin (exact fixed version numbers are not included in this dataset, so verify against the advisory). Until patched, limit untrusted low-privileged users' ability to execute code on sensitive hosts where Acrobat Reader is installed, and monitor for public PoC disclosures. Given no known exploitation, no KEV entry, and very low EPSS (0.1% over 30 days), standard patching cadence is likely sufficient unless local untrusted execution is common in your environment.
| Adobe Acrobat Reader | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not require user interaction. Scope is changed.
- Vendors
- adobe
- Products
- acrobat, acrobat dc, acrobat reader dc
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.