Remote Code Execution Vulnerability in Atril Document Viewer by MATE Desktop
CVE-2026-46529
What is CVE-2026-46529?
CVE-2026-46529 is a notable remote code execution vulnerability found in the Atril Document Viewer, which serves as the default document reading application within the MATE desktop environment for Linux. This vulnerability affects versions prior to 1.26.3 and 1.28.4, enabling malicious actors to execute arbitrary code on a victim's system simply by getting them to click a link embedded in a specially crafted PDF document. The attack can be facilitated by packaging the PDF as a polyglot file, making it both a valid PDF and an executable ELF shared library. This configuration allows for a seamless, one-click exploit that does not require user-specific settings, thus broadening its potential for misuse. The underlying cause of this vulnerability lies in how command lines are constructed from user-controlled fields in the PDF, without adequate sanitization, leading to the unintended execution of arbitrary commands when the file is opened.
Potential impact of CVE-2026-46529
-
Arbitrary Code Execution: The primary impact of this vulnerability is the ability for an attacker to execute arbitrary code on the affected system. Once executed, the attacker may gain the same permissions as the user who opened the malicious PDF, potentially leading to full system compromise.
-
Widespread Exploitation Potential: Given the nature of the vulnerability and its ease of exploitation (one-click execution), it creates considerable risk, especially in environments where Atril is commonly used. Users could inadvertently execute malicious code without comprehensive awareness, creating broader security concerns for organizations relying on this software.
-
Resource and Data Compromise: Successful exploitation may result not only in the compromise of the system itself but also in unauthorized access to sensitive organizational data and resources. This can lead to data breaches, loss of sensitive information, and potentially severe reputational damage for affected organizations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
atril < 1.26.3 < 1.26.3
atril >= 1.27.0, < 1.28.4 < 1.27.0, 1.28.4
