Junglewise Threat Intelligence

CVE-2026-47937: Adobe Acrobat Reader uncontrolled search path element

CVE-2026-47937 · Severity: high · CVSS 7.4 · Published 2026-06-09

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw in certain versions allows an attacker to run unauthorized commands on a user's computer if the user is tricked into opening a specially crafted file. This could lead to a full compromise of the user's workstation and sensitive data.

Technical details

Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain an uncontrolled search path element vulnerability (CWE-427). The flaw occurs when the application attempts to load a resource or library without a fully qualified path, allowing an attacker to place a malicious binary in a location searched by the application. Exploitation requires a local attacker to convince a victim to open a malicious file, leading to arbitrary code execution in the context of the current user. Although the CVSS vector indicates high privileges (PR:H) and a scope change (S:C), the primary impact is the execution of unauthorized code on the host system.

Affected products

  • Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Adobe released security bulletin APSB26-63

References

Related threats