CVE-2026-47937

Summary

Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Affected Software

VendorProductVersion RangeStatus
AdobeAcrobat DC0 <= 26.001.21651affected
AdobeAcrobat DC26.001.21662unaffected
AdobeAcrobat Reader DC0 <= 26.001.21651affected
AdobeAcrobat Reader DC26.001.21662unaffected
AdobeAcrobat 20240 <= 24.001.30365affected
AdobeAcrobat 202424.001.30383unaffected

Weaknesses

  • CWE-427: Uncontrolled Search Path Element (CWE-427)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References