CVE-2026-34622

Summary

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected Software

VendorProductVersion RangeStatus
AdobeAcrobat DC0 <= 26.001.21411affected
AdobeAcrobat DC26.001.21431unaffected
AdobeAcrobat Reader DC0 <= 26.001.21411affected
AdobeAcrobat Reader DC26.001.21431unaffected
AdobeAcrobat 20240 <= 24.001.30362 (Win), 24.001.30360 (Mac)affected
AdobeAcrobat 202424.001.30365unaffected

Weaknesses

  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References