Junglewise Threat Intelligence

CVE-2026-47923: Adobe Acrobat Reader out-of-bounds read

CVE-2026-47923 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where an attacker can trick a user into opening a specially crafted file to gain access to sensitive information stored in the computer's memory. This could lead to the exposure of private data or help an attacker bypass other security protections on the system.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The flaw occurs when the application reads data past the end of the intended buffer while processing a PDF file. An attacker can exploit this by creating a malicious file that, when opened by a user, allows the attacker to read sensitive information from the process memory. This is a local attack vector that requires user interaction (UI:R) and can result in high confidentiality impact.

Affected products

  • Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier versions

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References