Vulnerability Intelligence Report
Acrobat Reader | Incorrect Authorization (CWE-863)
CVE-2026-81996
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not require user interaction. Scope is changed.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.1
Impact Score:6.1
Temporal Score:8.8
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-863 ↗Incorrect Authorization (CWE-863)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Adobe | Adobe Acrobat | 0 <= 26.002.21900 (affected), 26.002.21901 (unaffected) |
| Adobe | Acrobat Reader | 0 <= 26.002.21900 (affected), 26.002.21901 (unaffected) |
| Adobe | Acrobat 2024 | 0 <= 24.001.30383 (affected), 24.001.30429 (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Adobe Systems Incorporated · Vendor · USA |
| Reserved | 2026-08-27T21:20:45 |
| Published | 2026-09-08T20:30:52 |
| Patch Date | 2026-09-08 |
| Last Updated | 2026-09-09T09:54:41 |
Community Chatter & Buzz