CVE-2026-80159
Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
- EPSS probability
- 0.11%
- CWE
- CWE-426
- Published
- 2026-09-08
- Last modified
- 2026-09-08
Affected products
- Adobe Adobe Acrobat
- Adobe Adobe Acrobat
- Adobe Acrobat Reader
- Adobe Acrobat Reader
- Adobe Acrobat 2024
- Adobe Acrobat 2024
Weakness type
Related vulnerabilities
- CVE-2026-0307 — GlobalProtect App: Local Privilege Escalation Vulnerabilities
- CVE-2026-81192 — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
- CVE-2026-78574 — Improper Assembly Resolution in Okta Hyperdrive Integration Plugin Registry Handling
- CVE-2026-69785 — Windows Smart Card Elevation of Privilege Vulnerability
- CVE-2026-69328 — Windows Storage Elevation of Privilege Vulnerability
- CVE-2026-84226 — OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local...
- CVE-2026-82862 — Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files
- CVE-2026-81697 — openssl_encrypt before 1.4.9 KDF Downgrade via CWD-relative Configuration