Multiple Permission Bypass Vulnerability in SumatraPDF Reader by Coherent Solutions
CVE-2026-107735

5.4MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107735?

SumatraPDF, a versatile multi-format reader for Windows, possesses a vulnerability in versions 3.6.1 and earlier where the initialization of policy settings allows for potential permission bypass. The method InitializePolicies() improperly initializes the sumatrapdfrestrict.ini configuration, leading to situations where the INI file's permissions may not effectively revoke access. This flaw can be exploited if a malformed configuration file or one with zero-valued permissions is deployed, resulting in unrestricted access to disk, network, printing, registry, clipboard, preference, and fullscreen functionalities. While the command-line 'restrict' option remains unaffected, no official fix is currently available for this vulnerability.

Affected Version(s)

sumatrapdf <= 3.6.1

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.