Executive brief
Adobe Acrobat Reader is a widely-used application for viewing and interacting with PDF documents in enterprise and consumer environments. An incorrect authorization flaw allows low-privileged attackers to gain elevated system privileges without requiring user interaction, potentially compromising document security controls and system integrity.
Technical details
This vulnerability is an incorrect authorization flaw in Adobe Acrobat Reader that enables privilege escalation. A low-privileged attacker can exploit this issue to gain elevated access without user interaction required, indicating the attack can be triggered automatically or remotely. The scope change indicates the impact extends beyond the vulnerable application itself. A patch or security update is expected from Adobe to address this authorization bypass.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed