6.3

CVE-2026-81994

Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Acrobat SwEdition classic Version >= 24.001.20604 < 24.001.30429
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Dc SwEdition continuous Version >= 15.008.20082 < 26.002.21901
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Reader Dc SwEdition continuous Version >= 15.008.20082 < 26.002.21901
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.229
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.3 1.8 4
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Adobe 8.2 1.8 5.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

https://helpx.adobe.com/security/products/acrobat/apsb26-141.html
Vendor Advisory