Multiple Permission Bypass Vulnerability in SumatraPDF Reader by Coherent Solutions
CVE-2026-107735
What is CVE-2026-107735?
SumatraPDF, a versatile multi-format reader for Windows, possesses a vulnerability in versions 3.6.1 and earlier where the initialization of policy settings allows for potential permission bypass. The method InitializePolicies() improperly initializes the sumatrapdfrestrict.ini configuration, leading to situations where the INI file's permissions may not effectively revoke access. This flaw can be exploited if a malformed configuration file or one with zero-valued permissions is deployed, resulting in unrestricted access to disk, network, printing, registry, clipboard, preference, and fullscreen functionalities. While the command-line 'restrict' option remains unaffected, no official fix is currently available for this vulnerability.
Affected Version(s)
sumatrapdf <= 3.6.1
