Incorrect Authorization Vulnerability in Adobe Acrobat Reader
CVE-2026-81997

6.3MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 September 2026

What is CVE-2026-81997?

Adobe Acrobat Reader is impacted by an incorrect authorization vulnerability that may enable attackers to bypass critical security measures and gain unauthorized write access. This issue necessitates user interaction, as exploitation occurs when a victim opens a specially crafted malicious file. Consequently, the scope of the attack is altered, elevating the risk associated with opening unverified documents.

Affected Version(s)

Acrobat 2024 0 <= 24.001.30383

Acrobat Reader 0 <= 26.002.21900

Adobe Acrobat 0 <= 26.002.21900

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.