Junglewise Threat Intelligence

CVE-2026-80159: Adobe Acrobat Reader untrusted search path privilege escalation

CVE-2026-80159 · Severity: medium · CVSS 4 · Published 2026-09-08

Executive brief

Adobe Acrobat Reader is affected by an untrusted search path vulnerability that allows an attacker to escalate privileges. An attacker with local access who tricks a user into opening a malicious file can gain elevated system permissions, potentially leading to full system compromise.

Technical details

The vulnerability is an untrusted search path issue in Adobe Acrobat Reader that can be leveraged to achieve privilege escalation. The attack requires user interaction—a victim must open a malicious PDF or related file. Exploitation depends on conditions beyond the attacker's control, but a successful exploit allows an attacker to execute code with elevated privileges on the affected system. The vulnerability was reported with a CVSS score of 4.0 (medium severity) and has not been observed actively exploited in the wild as of the publication date.

Affected products

  • Adobe Acrobat Reader

Timeline

  • 2026-09-08: disclosed

References

Related threats