Remote Code Execution Vulnerability in Atril Document Viewer by MATE Desktop
CVE-2026-46529

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-46529?

CVE-2026-46529 is a notable remote code execution vulnerability found in the Atril Document Viewer, which serves as the default document reading application within the MATE desktop environment for Linux. This vulnerability affects versions prior to 1.26.3 and 1.28.4, enabling malicious actors to execute arbitrary code on a victim's system simply by getting them to click a link embedded in a specially crafted PDF document. The attack can be facilitated by packaging the PDF as a polyglot file, making it both a valid PDF and an executable ELF shared library. This configuration allows for a seamless, one-click exploit that does not require user-specific settings, thus broadening its potential for misuse. The underlying cause of this vulnerability lies in how command lines are constructed from user-controlled fields in the PDF, without adequate sanitization, leading to the unintended execution of arbitrary commands when the file is opened.

Potential impact of CVE-2026-46529

  1. Arbitrary Code Execution: The primary impact of this vulnerability is the ability for an attacker to execute arbitrary code on the affected system. Once executed, the attacker may gain the same permissions as the user who opened the malicious PDF, potentially leading to full system compromise.

  2. Widespread Exploitation Potential: Given the nature of the vulnerability and its ease of exploitation (one-click execution), it creates considerable risk, especially in environments where Atril is commonly used. Users could inadvertently execute malicious code without comprehensive awareness, creating broader security concerns for organizations relying on this software.

  3. Resource and Data Compromise: Successful exploitation may result not only in the compromise of the system itself but also in unauthorized access to sensitive organizational data and resources. This can lead to data breaches, loss of sensitive information, and potentially severe reputational damage for affected organizations.

Affected Version(s)

atril < 1.26.3 < 1.26.3

atril >= 1.27.0, < 1.28.4 < 1.27.0, 1.28.4

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.