# CVE-2026-80159

## Summary

- **CVE ID:** CVE-2026-80159
- **Severity:** MEDIUM
- **CVSS Score:** 4 (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N)
- **CWE:** CWE-426
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 8, 2026

## Description

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected Products

- Adobe — Adobe Acrobat (0)
- Adobe — Adobe Acrobat (26.002.21901)
- Adobe — Acrobat Reader (0)
- Adobe — Acrobat Reader (26.002.21901)
- Adobe — Acrobat 2024 (0)
- Adobe — Acrobat 2024 (24.001.30429)

## References

- [CNA](https://helpx.adobe.com/security/products/acrobat/apsb26-141.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.11%
- **EPSS Percentile:** 1.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._