ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI published advisory ZDI-26-670 for an out-of-bounds read information disclosure flaw (CVE-2026-81991) in Adobe Acrobat Pro DC.
The Zero Day Initiative disclosed ZDI-26-670, an out-of-bounds read in the Doc object of Adobe Acrobat Pro DC. A remote attacker could disclose sensitive information from affected installations if the user opens a malicious file or page. ZDI rated the issue 3.3 on the CVSS scale and assigned CVE-2026-81991.
- Out-of-bounds read in the Doc object leaks sensitive information from Acrobat Pro DC
- Exploitation requires user interaction with a malicious file or page
- ZDI assigned CVSS 3.3 and CVE-2026-81991
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81991 | Out-of-Bounds Read Information Disclosure in Adobe Acrobat Reader (Doc Object) Adobe Acrobat Reader contains an out-of-bounds read vulnerability (CWE-125) in its handling of Doc objects, per the ZDI-26-670 advisory, allowing the application to read beyond intended memory boundaries and potentially expose sensitive memory contents. An attacker triggers it by crafting a malicious PDF and convincing a victim to open it in Acrobat Reader, since exploitation requires local access and user interaction (AV:L/UI:R). A successful attack yields disclosure of sensitive information only; the CVSS vector (C:H/I:N/A:N) shows no integrity or availability impact and no implied code execution. All users of the affected Acrobat Reader/Acrobat DC versions are potentially exposed, though Adobe has not published the exact version ranges in the available data. Exploitation has not been observed: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days (7th percentile). Do: Update Acrobat Reader/Acrobat DC using the fix in Adobe's security bulletin for CVE-2026-81991 as soon as it is available; because exact affected version ranges are not provided here, verify your installed Reader/DC build against Adobe's advisory. Until patched, avoid opening PDFs from untrusted sources and consider filtering unexpected PDF attachments at the email gateway, since exploitation requires a user to open a malicious file. | 5.5 | <1% |
| masshundreds of millions of users/devices (Acrobat Reader is the dominant desktop PDF viewer) |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81991.
This source does not provide full text. Read it at zerodayinitiative.com.